Cisco Hyperflex: How We Got RCE Through Login Form and Other Findings
swarm.ptsecurity.com | research | #rce | #vulnerability-research | #cve | #cisco | #command-injection
Summary
An assessment of Cisco HyperFlex HX that found three vulnerabilities: command injection in the installer VM (CVE-2021-1497, CVSS 9.8) and the data platform (CVE-2021-1498), plus a file upload flaw (CVE-2021-1499) — including RCE reached through the login form.
- Published
- Collected
Skip to content