cbcvebase.
CVE-2021-1388
published 2021-02-24

CVE-2021-1388: A vulnerability in an API endpoint of Cisco ACI Multi-Site Orchestrator (MSO) installed on the Application Services Engine could allow an unauthenticated…

PriorityP181critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
EPSS
14.36%
96.2th percentile
A vulnerability in an API endpoint of Cisco ACI Multi-Site Orchestrator (MSO) installed on the Application Services Engine could allow an unauthenticated, remote attacker to bypass authentication on an affected device. The vulnerability is due to improper token validation on a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted request to the affected API. A successful exploit could allow the attacker to receive a token with administrator-level privileges that could be used to authenticate to the API on affected MSO and managed Cisco Application Policy Infrastructure Controller (APIC) devices.

Affected

4 ranges
VendorProductVersion rangeFixed in
ciscoaci_multi-site_orchestrator>= 3.0 < 3.0\(3m\)3.0\(3m\)
ciscoaci_multi-site_orchestrator_application_services_engine_deployment
ciscoapplication_policy_infrastructure_controller
ciscocisco_aci_multi-site_orchestrator_software

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability targets a specific API endpoint on Cisco ACI Multi-Site Orchestrator (MSO) installed on Application Services Engine; monitor for unauthenticated requests to MSO API endpoints that return administrator-level tokens.
  • A successful exploit yields an administrator-level token; alert on any unauthenticated API session that receives or presents an admin-privilege token on MSO or managed APIC devices.
  • Track Cisco Bug ID CSCvw14141 for vendor patch and detection signature updates related to this authentication bypass.
  • ·The vulnerability only affects Cisco ACI MSO when deployed on the Application Services Engine; MSO deployments on other platforms are not affected by this specific flaw.
  • ·There are no workarounds available; the only remediation is applying Cisco's released software updates.

CVSS provenance

nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_cisco10.0CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.