A vulnerability in the hxterm service of Cisco HyperFlex Software could allow an unauthenticated, local attacker to gain root access to all nodes in the cluster. The vulnerability is due to insufficient authentication controls. An attacker could exploit this vulnerability by connecting to the hxterm service as a non-privileged, local user. A successful exploit could allow the attacker to gain root access to all member nodes of the HyperFlex cluster. This vulnerability affects Cisco HyperFlex Software Releases prior to 3.5(2a).
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published: 2019-02-21T19:00:00Z

Updated: 2024-09-17T02:16:44.512Z

Reserved: 2018-12-06T00:00:00

Link: CVE-2019-1664

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-02-21T19:29:00.367

Modified: 2020-10-05T20:21:37.210

Link: CVE-2019-1664

cve-icon Redhat

No data.