A vulnerability in the hxterm service of Cisco HyperFlex Software could allow an unauthenticated, local attacker to gain root access to all nodes in the cluster. The vulnerability is due to insufficient authentication controls. An attacker could exploit this vulnerability by connecting to the hxterm service as a non-privileged, local user. A successful exploit could allow the attacker to gain root access to all member nodes of the HyperFlex cluster. This vulnerability affects Cisco HyperFlex Software Releases prior to 3.5(2a).
History

Wed, 20 Nov 2024 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published: 2019-02-21T19:00:00Z

Updated: 2024-11-20T17:27:50.205Z

Reserved: 2018-12-06T00:00:00

Link: CVE-2019-1664

cve-icon Vulnrichment

Updated: 2024-08-04T18:20:28.357Z

cve-icon NVD

Status : Analyzed

Published: 2019-02-21T19:29:00.367

Modified: 2020-10-05T20:21:37.210

Link: CVE-2019-1664

cve-icon Redhat

No data.