Known vulnerabilities in Cisco HyperFlex
Vendor:
Cisco Systems, Inc
Software:
Cisco HyperFlex
Software CPE:
cpe:2.3:h:cisco_systems:cisco_hyperflex:*:*:*:*:*:*:*:*
Website:
https://www.cisco.com
Total vulnerabilities:
7
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.7
Breakdown by Severity Chart
Vulnerabilities (7)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU45900 - Cleartext Storage of Sensitive Information CVE-2020-3389 |
CWE-312 | Low | - | 21.08.2020 |
SB2020082108 |
||
| #VU20361 - Use of Hard-coded Cryptographic Key CVE-2019-12621 |
CWE-321 | Medium | 4.0.1a | 22.08.2019 |
SB2019082206 |
||
| #VU17837 - Exposure of sensitive information to an unauthorized actor CVE-2019-1666 |
CWE-200 | Low | 3.5.2a | 22.02.2019 |
SB2019022203 |
||
| #VU17836 - Permissions, Privileges, and Access Controls CVE-2019-1664 |
CWE-264 | Low | 3.5.2a | 22.02.2019 |
SB2019022203 |
||
| #VU17835 - Insufficient Verification of Data Authenticity CVE-2019-1667 |
CWE-345 | Low | 3.5.2a | 22.02.2019 |
SB2019022203 |
||
| #VU17834 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2018-15380 |
CWE-78 | Medium | 3.5.2a | 22.02.2019 |
SB2019022203 |
||
| #VU17833 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2019-1665 |
CWE-79 | Low | 3.5.1a | 22.02.2019 |
SB2019022203 |