HTTP: Cisco HyperFlex HX Remote Command Execution

This signature detects attempts to exploit a known vulnerability against Cisco. A successful attack can lead to arbitrary code execution.

Extended Description

Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

Short Name
HTTP:CISCO:HYPERFLEX-HX-RCE
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2021-1497 CVE-2021-1498 Cisco Command Execution HX HyperFlex Remote
Release Date
05/27/2021
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3590
False Positive
Unknown
CVSS Score

7.5

10.0

Found a potential security threat?