Skip to main content

Vendor/product archive

cisco / hyperflex_hx_data_platform CVEs

Beta · best-effort

15 CVEs tagged to cisco / hyperflex_hx_data_platform2 Critical, 4 High, 8 Medium, 1 Low, 0 Unrated.

CVE-2023-20263

Published Sep 6, 2023

A vulnerability in the web-based management interface of Cisco HyperFlex HX Data Platform could allow an unauthenticated, remote attacker to redirect a user to a malicious web pag…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-1499

Published May 6, 2021

A vulnerability in the web-based management interface of Cisco HyperFlex HX Data Platform could allow an unauthenticated, remote attacker to upload files to an affected device. Th…

CVSS 5.3 · Medium

CVE-2021-1498

Published May 6, 2021

Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against a…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
52.6
KEV listed

CVE-2021-1497

Published May 6, 2021

Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against a…

CVSS 9.8 · Critical
evidence mentions
5
Buzz score
49.4
KEV listed

CVE-2019-1958

Published Aug 8, 2019

A vulnerability in the web-based management interface of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) at…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-1667

Published Feb 21, 2019

A vulnerability in the Graphite interface of Cisco HyperFlex software could allow an authenticated, local attacker to write arbitrary data to the Graphite interface. The vulnerabi…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2019-1666

Published Feb 21, 2019

A vulnerability in the Graphite service of Cisco HyperFlex software could allow an unauthenticated, remote attacker to retrieve data from the Graphite service. The vulnerability i…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-1665

Published Feb 21, 2019

A vulnerability in the web-based management interface of Cisco HyperFlex software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack ag…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-1664

Published Feb 21, 2019

A vulnerability in the hxterm service of Cisco HyperFlex Software could allow an unauthenticated, local attacker to gain root access to all nodes in the cluster. The vulnerability…

CVSS 7.8 · High
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2018-15380

Published Feb 20, 2019

A vulnerability in the cluster service manager of Cisco HyperFlex Software could allow an unauthenticated, adjacent attacker to execute commands as the root user. The vulnerabilit…

CVSS 8.8 · High
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2018-15429

Published Oct 5, 2018

A vulnerability in the web-based UI of Cisco HyperFlex HX Data Platform Software could allow an unauthenticated, remote attacker to access sensitive information on an affected sys…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-15423

Published Oct 5, 2018

A vulnerability in the web UI of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to affect the integrity of a device via a clickjacking attack. The vulner…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-15407

Published Oct 5, 2018

A vulnerability in the installation process of Cisco HyperFlex Software could allow an authenticated, local attacker to read sensitive information. The vulnerability is due to ins…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-15382

Published Oct 5, 2018

A vulnerability in Cisco HyperFlex Software could allow an unauthenticated, remote attacker to generate valid, signed session tokens. The vulnerability is due to a static signing…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2017-12315

Published Nov 16, 2017

A vulnerability in system logging when replication is being configured with the Cisco HyperFlex System could allow an authenticated, local attacker to view sensitive information t…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-15 of 15 CVEsPage 1 of 1