CVE-2019-1664
HIGHCisco HyperFlex HX Data Platform < 3.5(2a) - Unauthenticated Privilege Escalation via hxterm Service
Title source: llmDescription
A vulnerability in the hxterm service of Cisco HyperFlex Software could allow an unauthenticated, local attacker to gain root access to all nodes in the cluster. The vulnerability is due to insufficient authentication controls. An attacker could exploit this vulnerability by connecting to the hxterm service as a non-privileged, local user. A successful exploit could allow the attacker to gain root access to all member nodes of the HyperFlex cluster. This vulnerability affects Cisco HyperFlex Software Releases prior to 3.5(2a).
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
x_refsource_cisco
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190220-chn-root-access
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/107103
Scores
CVSS v3
7.8
EPSS
0.0033
EPSS Percentile
25.2%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-284
CWE-287
Status
published
Products (12)
cisco/hyperflex_hx_data_platform
2.6\(1a\)
cisco/hyperflex_hx_data_platform
2.6\(1b\)
cisco/hyperflex_hx_data_platform
2.6\(1d\)
cisco/hyperflex_hx_data_platform
2.6\(1e\)
cisco/hyperflex_hx_data_platform
3.0\(1a\)
cisco/hyperflex_hx_data_platform
3.0\(1b\)
cisco/hyperflex_hx_data_platform
3.0\(1c\)
cisco/hyperflex_hx_data_platform
3.0\(1d\)
cisco/hyperflex_hx_data_platform
3.0\(1e\)
cisco/hyperflex_hx_data_platform
3.0\(1h\)
... and 2 more
Published
Feb 21, 2019
Tracked Since
Feb 18, 2026