7.8
CVSSv3

CVE-2019-1664

Published: 21/02/2019 Updated: 05/10/2020
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

A vulnerability in the hxterm service of Cisco HyperFlex Software could allow an unauthenticated, local malicious user to gain root access to all nodes in the cluster. The vulnerability is due to insufficient authentication controls. An attacker could exploit this vulnerability by connecting to the hxterm service as a non-privileged, local user. A successful exploit could allow the malicious user to gain root access to all member nodes of the HyperFlex cluster. This vulnerability affects Cisco HyperFlex Software Releases before 3.5(2a).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco hyperflex hx data platform 2.6\\(1e\\)

cisco hyperflex hx data platform 3.0\\(1a\\)

cisco hyperflex hx data platform 3.0\\(1b\\)

cisco hyperflex hx data platform 3.0\\(1c\\)

cisco hyperflex hx data platform 2.6\\(1a\\)

cisco hyperflex hx data platform 2.6\\(1d\\)

cisco hyperflex hx data platform 3.0\\(1d\\)

cisco hyperflex hx data platform 3.0\\(1h\\)

cisco hyperflex hx data platform 3.5\\(1a\\)

cisco hyperflex hx data platform 2.6\\(1b\\)

cisco hyperflex hx data platform 3.0\\(1e\\)

cisco hyperflex hx data platform 3.0\\(1i\\)

Vendor Advisories

A vulnerability in the hxterm service of Cisco HyperFlex Software could allow an unauthenticated, local attacker to gain root access to all nodes in the cluster The vulnerability is due to insufficient authentication controls An attacker could exploit this vulnerability by connecting to the hxterm service as a non-privileged, local user A succes ...