CVE-2018-15382 describes a critical vulnerability in Cisco HyperFlex Software, specifically affecting the hyperflex_hx_data_platform. This flaw allows an unauthenticated, remote attacker to generate valid, signed session tokens due to a static signing key present across all HyperFlex systems. With a CVSS score of 8.6 (HIGH), the vulnerability has a network attack vector and low attack complexity, potentially leading to unauthorized access to the HyperFlex Web UI and significant impact on availability. While no active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion has been observed, the vulnerability's high FAUCET Risk Score of 66/100 indicates its potential severity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0\(1a\)CPE matchmatch criteria | cpe:2.3:o:cisco:hyperflex_hx_data_platform:3.0\(1a\):*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.