CVE-2018-15380 is a high-severity vulnerability in Cisco HyperFlex Software releases prior to 3.5(2a), specifically affecting the cluster service manager. This flaw, stemming from insufficient input validation, allows an unauthenticated, adjacent attacker to inject and execute commands as the root user. The attack requires adjacent network access and has low complexity, leading to complete compromise of confidentiality, integrity, and availability. While no public exploit code (Metasploit, Nuclei, ExploitDB) is available and it's not on the KEV catalog, there has been some community discussion and media coverage, indicating awareness of the vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0\(1a\)CPE matchmatch criteria | cpe:2.3:a:cisco:hyperflex_hx_data_platform:3.0\(1a\):*:*:*:*:*:*:* | ||
3.5\(1a\)CPE matchmatch criteria | cpe:2.3:a:cisco:hyperflex_hx_data_platform:3.5\(1a\):*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.