CVE-2019-1975: Cisco HyperFlex HX220C Af m5 Firmware
Medium severity, CVSS 6.1. EPSS: 1.2% chance of exploitation in the next 30 days.
A vulnerability in the web-based interface of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to execute a cross-frame scripting (XFS) attack on an affected device. This vulnerability is due to insufficient HTML iframe protection. An attacker could exploit this vulnerability by directing a user to an attacker-controlled web page that contains a malicious HTML iframe. A successful exploit could allow the attacker to conduct clickjacking or other clientside browser attacks.
Affected products
- Cisco HyperFlex HX220C Af m5 Firmware: up to and including 3.5.2f; version 4.0(1a) only
- Cisco HyperFlex HX220C Edge m5 Firmware: up to and including 3.5.2f; version 4.0(1a) only
- Cisco HyperFlex HX220C m5 Firmware: up to and including 3.5.2f; version 4.0(1a) only
- Cisco HyperFlex HX240C Af m5 Firmware: up to and including 3.5.2f; version 4.0(1a) only
- Cisco HyperFlex HX240C m5 Firmware: up to and including 3.5.2f; version 4.0(1a) only
Published 2019-09-18. Last modified 2026-06-17.