Blog | G5 Cyber Security

Cisco HyperFlex Software Unauthenticated Root Access Vulnerability

A vulnerability in the hxterm service of Cisco HyperFlex Software could allow an unauthenticated, local attacker to gain root access to all nodes in the cluster. The vulnerability is due to insufficient authentication controls. Cisco has released software updates that address this vulnerability. A workaround for this vulnerability is available for customers who cannot upgrade to a fixed release. Customers should only download software for which they have a valid license, procured from Cisco directly, or through a Cisco authorized reseller or partner.”]

Source: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190220-chn-root-access

Exit mobile version