Hyperflex Hx Data Platform

Vendor:

First CVE: Nov 16, 2017 · Active for 8 years

15
Total CVEs
More Total CVEs than 92% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 36% of tracked products
13.3%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Hyperflex Hx Data Platform over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 16, 2017
8 years ago
Most Recent CVE
Sep 6, 2023
1,052 days ago

CVE Severity & Scoring

Hyperflex Hx Data Platform15 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local4 (26.7%)
Network10 (66.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (6.7%)
Attack Complexity
Low15 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None11 (73.3%)
Unknown0 (0.0%)
Required4 (26.7%)
Privileges Required
Low3 (20.0%)
High1 (6.7%)
None11 (73.3%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an
May 6, 20219.898YESYES
Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an
May 6, 20219.898YESYES
A vulnerability in the web-based management interface of Cisco HyperFlex HX Data Platform could allow an unauthenticated, remote attacker to upload files to an affected device. Thi
May 6, 20215.379NOYES
A vulnerability in the cluster service manager of Cisco HyperFlex Software could allow an unauthenticated, adjacent attacker to execute commands as the root user. The vulnerability
Feb 20, 20198.828NONO
A vulnerability in the web-based management interface of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) att
Aug 8, 20198.826NONO
A vulnerability in Cisco HyperFlex Software could allow an unauthenticated, remote attacker to generate valid, signed session tokens. The vulnerability is due to a static signing k
Oct 5, 20188.626NONO
A vulnerability in the hxterm service of Cisco HyperFlex Software could allow an unauthenticated, local attacker to gain root access to all nodes in the cluster. The vulnerability
Feb 21, 20197.824NONO
A vulnerability in the web-based management interface of Cisco HyperFlex software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack aga
Feb 21, 20196.122NONO
A vulnerability in the Graphite service of Cisco HyperFlex software could allow an unauthenticated, remote attacker to retrieve data from the Graphite service. The vulnerability is
Feb 21, 20195.321NONO
A vulnerability in system logging when replication is being configured with the Cisco HyperFlex System could allow an authenticated, local attacker to view sensitive information th
Nov 16, 20176.021NONO

Exploit Exposure

Signals from CVEs in this product scope (15 CVEs).

CISA KEV
2 CVEs
13.3% of CVEs· 98th percentile
Metasploit
3 CVEs
20.0% of CVEs· 97th percentile
Nuclei
3 CVEs
20.0% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (15 CVEs).

Media Mentions

Signals from CVEs in this product scope (15 CVEs).

Top CNAs Publishing CVEs For Hyperflex Hx Data Platform

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
5.516.10.5%00
5.016.10.5%00
3.5\(1a\)46.31.0%00
3.0\(1i\)45.60.9%00
3.0\(1h\)45.60.9%00
3.0\(1e\)45.60.9%00
3.0\(1d\)45.60.9%00
3.0\(1c\)45.60.9%00
3.0\(1b\)45.60.9%00
3.0\(1a\)96.20.9%00
2.6\(1e\)45.60.9%00
2.6\(1d\)65.41.0%00
2.6\(1b\)45.60.9%00
2.6\(1a\)55.70.8%00