Hyperflex Hx Data Platform
Vendor:
First CVE: Nov 16, 2017 · Active for 8 years
15
Total CVEs
More Total CVEs than 92% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 36% of tracked products
13.3%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Hyperflex Hx Data Platform over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 16, 2017
8 years ago
Most Recent CVE
Sep 6, 2023
1,052 days ago
CVE Severity & Scoring
Hyperflex Hx Data Platform15 CVEs
53%
27%
13%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local4 (26.7%)
Network10 (66.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (6.7%)
Attack Complexity
Low15 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None11 (73.3%)
Unknown0 (0.0%)
Required4 (26.7%)
Privileges Required
Low3 (20.0%)
High1 (6.7%)
None11 (73.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-1498CRITICAL Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an | May 6, 2021 | 9.8 | 98 | YES | YES |
CVE-2021-1497CRITICAL Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an | May 6, 2021 | 9.8 | 98 | YES | YES |
CVE-2021-1499MEDIUM A vulnerability in the web-based management interface of Cisco HyperFlex HX Data Platform could allow an unauthenticated, remote attacker to upload files to an affected device. Thi | May 6, 2021 | 5.3 | 79 | NO | YES |
CVE-2018-15380HIGH A vulnerability in the cluster service manager of Cisco HyperFlex Software could allow an unauthenticated, adjacent attacker to execute commands as the root user. The vulnerability | Feb 20, 2019 | 8.8 | 28 | NO | NO |
CVE-2019-1958HIGH A vulnerability in the web-based management interface of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) att | Aug 8, 2019 | 8.8 | 26 | NO | NO |
CVE-2018-15382HIGH A vulnerability in Cisco HyperFlex Software could allow an unauthenticated, remote attacker to generate valid, signed session tokens. The vulnerability is due to a static signing k | Oct 5, 2018 | 8.6 | 26 | NO | NO |
CVE-2019-1664HIGH A vulnerability in the hxterm service of Cisco HyperFlex Software could allow an unauthenticated, local attacker to gain root access to all nodes in the cluster. The vulnerability | Feb 21, 2019 | 7.8 | 24 | NO | NO |
CVE-2019-1665MEDIUM A vulnerability in the web-based management interface of Cisco HyperFlex software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack aga | Feb 21, 2019 | 6.1 | 22 | NO | NO |
CVE-2019-1666MEDIUM A vulnerability in the Graphite service of Cisco HyperFlex software could allow an unauthenticated, remote attacker to retrieve data from the Graphite service. The vulnerability is | Feb 21, 2019 | 5.3 | 21 | NO | NO |
CVE-2017-12315MEDIUM A vulnerability in system logging when replication is being configured with the Cisco HyperFlex System could allow an authenticated, local attacker to view sensitive information th | Nov 16, 2017 | 6.0 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (15 CVEs).
CISA KEV
2 CVEs
13.3% of CVEs· 98th percentile
Metasploit
3 CVEs
20.0% of CVEs· 97th percentile
Nuclei
3 CVEs
20.0% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (15 CVEs).
Media Mentions
Signals from CVEs in this product scope (15 CVEs).
Top CNAs Publishing CVEs For Hyperflex Hx Data Platform
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.5 | 1 | 6.1 | 0.5% | 0 | 0 |
| 5.0 | 1 | 6.1 | 0.5% | 0 | 0 |
| 3.5\(1a\) | 4 | 6.3 | 1.0% | 0 | 0 |
| 3.0\(1i\) | 4 | 5.6 | 0.9% | 0 | 0 |
| 3.0\(1h\) | 4 | 5.6 | 0.9% | 0 | 0 |
| 3.0\(1e\) | 4 | 5.6 | 0.9% | 0 | 0 |
| 3.0\(1d\) | 4 | 5.6 | 0.9% | 0 | 0 |
| 3.0\(1c\) | 4 | 5.6 | 0.9% | 0 | 0 |
| 3.0\(1b\) | 4 | 5.6 | 0.9% | 0 | 0 |
| 3.0\(1a\) | 9 | 6.2 | 0.9% | 0 | 0 |
| 2.6\(1e\) | 4 | 5.6 | 0.9% | 0 | 0 |
| 2.6\(1d\) | 6 | 5.4 | 1.0% | 0 | 0 |
| 2.6\(1b\) | 4 | 5.6 | 0.9% | 0 | 0 |
| 2.6\(1a\) | 5 | 5.7 | 0.8% | 0 | 0 |