Cisco HyperFlex web interface has critical flaw that lets attackers get root and execute arbitrary commands
(2021/05/07)
- Reference: 1620366729
- News link: https://www.theregister.co.uk/2021/05/07/cisco_hyperflex_critical_flaw/
- Source link:
Cisco has revealed a pair of critical bugs in its HyperFlex hyperconverged infrastructure product.
CVE-2021-1497 impacts the HyperFlex HX Installer Virtual Machine and means an unauthenticated, remote attacker could perform a command injection attack on a web management console that gives them root access and allows them to execute arbitrary commands on an affected device.
CVE-2021-1498 also allows an attacker to use command injection on the management interface, with login as the tomcat8 user. Again, execution of arbitrary commands is on offer.
[1]
[2]
[3]
Cisco’s [4]advisory gives the same explanation for both flaws:
This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface.
CVE-2021-1497 is rated 9.8 on the ten-point Common Vulnerability Scoring System. CVE-2021-1498 is a mere 7.3.
[5]
HyperFlex versions before 4.0, 4.0 and 4.5 are all impacted by one or both flaws. Migration to a patched version of the software is the fix.
[6]We need to talk about criminal adversaries who want you to eat undercooked onion rings
[7]Cisco issues blizzard of end-of-life notices for Nexus 3K and 7K switches
[8]Cisco Webex bug allowed anyone to join a password-protected meeting
[9]Cisco warns VMware vCenter bug puts hyperconverged tin in ‘unrecoverable’ state
Cisco suggests HyperFlex as multi-hypervisor converged infrastructure that can run in the mightiest data centre or weirdest edge location. The HX VM is used to install and manage VMs, so the flaws have enormous potential for a miscreant to go on a rampage.
Thankfully, Cisco says it’s not seen the flaws exploited in the wild. Nikita Abramov and Mikhail Klyuchnikov of Positive Technologies reported the vulnerabilities. ®
Get our [10]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YJUPvWMQQldrSTdCeXNtXwAAAEQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YJUPvWMQQldrSTdCeXNtXwAAAEQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YJUPvWMQQldrSTdCeXNtXwAAAEQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hyperflex-rce-TjjNrkpR
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YJUPvWMQQldrSTdCeXNtXwAAAEQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] http://www.theregister.com/2021/04/20/cisco_talos_corosi_fryer_flaws/
[7] http://www.theregister.com/2021/03/09/cisco_nexus_switch/
[8] http://www.theregister.com/2020/01/27/cisco_webex_bug_let_anyone_join_a_passwordprotected_meeting/
[9] http://www.theregister.com/2020/10/20/cisco_hyperflex_vmware_warning/
[10] https://whitepapers.theregister.com/
CVE-2021-1497 impacts the HyperFlex HX Installer Virtual Machine and means an unauthenticated, remote attacker could perform a command injection attack on a web management console that gives them root access and allows them to execute arbitrary commands on an affected device.
CVE-2021-1498 also allows an attacker to use command injection on the management interface, with login as the tomcat8 user. Again, execution of arbitrary commands is on offer.
[1]
[2]
[3]
Cisco’s [4]advisory gives the same explanation for both flaws:
This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface.
CVE-2021-1497 is rated 9.8 on the ten-point Common Vulnerability Scoring System. CVE-2021-1498 is a mere 7.3.
[5]
HyperFlex versions before 4.0, 4.0 and 4.5 are all impacted by one or both flaws. Migration to a patched version of the software is the fix.
[6]We need to talk about criminal adversaries who want you to eat undercooked onion rings
[7]Cisco issues blizzard of end-of-life notices for Nexus 3K and 7K switches
[8]Cisco Webex bug allowed anyone to join a password-protected meeting
[9]Cisco warns VMware vCenter bug puts hyperconverged tin in ‘unrecoverable’ state
Cisco suggests HyperFlex as multi-hypervisor converged infrastructure that can run in the mightiest data centre or weirdest edge location. The HX VM is used to install and manage VMs, so the flaws have enormous potential for a miscreant to go on a rampage.
Thankfully, Cisco says it’s not seen the flaws exploited in the wild. Nikita Abramov and Mikhail Klyuchnikov of Positive Technologies reported the vulnerabilities. ®
Get our [10]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YJUPvWMQQldrSTdCeXNtXwAAAEQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YJUPvWMQQldrSTdCeXNtXwAAAEQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YJUPvWMQQldrSTdCeXNtXwAAAEQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hyperflex-rce-TjjNrkpR
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YJUPvWMQQldrSTdCeXNtXwAAAEQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] http://www.theregister.com/2021/04/20/cisco_talos_corosi_fryer_flaws/
[7] http://www.theregister.com/2021/03/09/cisco_nexus_switch/
[8] http://www.theregister.com/2020/01/27/cisco_webex_bug_let_anyone_join_a_passwordprotected_meeting/
[9] http://www.theregister.com/2020/10/20/cisco_hyperflex_vmware_warning/
[10] https://whitepapers.theregister.com/
State sponsored Chinese backdoors again ...
Andy The Hat
What?
Not Chinese?
Are you sure?
But the Trumpmeister assured us that any security hole in Chinese software was not a result of piss-poor programming practice but deliberate act with malicious intent. No American software has deliberate holes so, as it's American, it's not malicious! But that means it must instead be piss ... oh dear.
Is there any other Huawei to look at this?
"insufficient validation of user-supplied input"
Aka sloppy programming.
On a platform that is specifically touted to be the tool to manage VMs.
Well done, Cisco. With you around, who needs Huawei ?