CVE-2019-1664 is a high-severity vulnerability in Cisco HyperFlex Software releases prior to 3.5(2a) that allows an unauthenticated, local attacker to gain root access to all nodes in a HyperFlex cluster. This flaw stems from insufficient authentication controls within the hxterm service. An attacker could exploit this by connecting to the service as a non-privileged local user, leading to complete compromise of the cluster. The vulnerability has a CVSS score of 7.8 (HIGH), indicating a low attack complexity and requiring local access with low privileges, but resulting in high impacts to confidentiality, integrity, and availability. While there is no evidence of active exploitation (KEV listed as No), there is no public exploit code available in Metasploit, Nuclei, or ExploitDB. Despite the lack of public exploit code, the vulnerability has garnered some community discussion and media coverage, with one article from SecurityWeek highlighting Cisco's patch release. Its EPSS score is low, suggesting a low probability of exploitation in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.6\(1a\)CPE matchmatch criteria | cpe:2.3:o:cisco:hyperflex_hx_data_platform:2.6\(1a\):*:*:*:*:*:*:* | ||
2.6\(1b\)CPE matchmatch criteria | cpe:2.3:o:cisco:hyperflex_hx_data_platform:2.6\(1b\):*:*:*:*:*:*:* | ||
2.6\(1d\)CPE matchmatch criteria | cpe:2.3:o:cisco:hyperflex_hx_data_platform:2.6\(1d\):*:*:*:*:*:*:* | ||
2.6\(1e\)CPE matchmatch criteria | cpe:2.3:o:cisco:hyperflex_hx_data_platform:2.6\(1e\):*:*:*:*:*:*:* | ||
3.0\(1a\)CPE matchmatch criteria | cpe:2.3:o:cisco:hyperflex_hx_data_platform:3.0\(1a\):*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.