Vulnerability Intelligence Report
Cisco HyperFlex HX Data Platform File Upload Vulnerability
CVE-2021-1499
A vulnerability in the web-based management interface of Cisco HyperFlex HX Data Platform could allow an unauthenticated, remote attacker to upload files to an affected device. This vulnerability is due to missing authentication for the upload function. An attacker could exploit this vulnerability by sending a specific HTTP request to an affected device. A successful exploit could allow the attacker to upload files to the affected device with the permissions of the tomcat8 user.
Nuclei Template
CVSS Base Score
5.3
MEDIUM
Exploitability:3.9
Impact Score:1.5
EPSS Probability:80.43%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-306 ↗CWE-306
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Cisco | Cisco HyperFlex HX Data Platform | n/a (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Cisco Systems, Inc. · Hosted Service · USA |
| Reserved | 2020-11-13T00:00:00 |
| Published | 2021-05-06T12:41:36 |
| Patch Date | 2021-05-05 |
| Last Updated | 2024-11-08T23:20:10 |
Community Chatter & Buzz