CVE-2021-1579
published 2021-08-25CVE-2021-1579: A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Controller…
PriorityP261high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
2.13%
80.0th percentile
A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Controller (Cloud APIC) could allow an authenticated, remote attacker with Administrator read-only credentials to elevate privileges on an affected system. This vulnerability is due to an insufficient role-based access control (RBAC). An attacker with Administrator read-only credentials could exploit this vulnerability by sending a specific API request using an app with admin write credentials. A successful exploit could allow the attacker to elevate privileges to Administrator with write privileges on the affected device.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | application_policy_infrastructure_controller | < 3.2\(10f\) | 3.2\(10f\) |
| cisco | application_policy_infrastructure_controller | >= 4.0 < 4.2\(7l\) | 4.2\(7l\) |
| cisco | application_policy_infrastructure_controller | >= 5.0 < 5.2\(2f\) | 5.2\(2f\) |
| cisco | application_policy_infrastructure_controller_app | — | — |
| cisco | cisco_application_policy_infrastructure_controller | — | — |
| cisco | cloud_application_policy_infrastructure_controller | < 3.2\(10f\) | 3.2\(10f\) |
| cisco | cloud_application_policy_infrastructure_controller | >= 4.0 < 4.2\(7l\) | 4.2\(7l\) |
| cisco | cloud_application_policy_infrastructure_controller | >= 5.0 < 5.2\(2f\) | 5.2\(2f\) |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit involves sending a specific API request using an app with admin write credentials, originating from an account with Administrator read-only credentials — monitor for API calls that result in privilege changes from read-only admin accounts ↗
- →Alert on privilege escalation to Administrator with write privileges on Cisco APIC/Cloud APIC, especially when the originating session was authenticated with read-only credentials ↗
- →Track Cisco Bug ID CSCvw57164 for patch and indicator updates related to this RBAC bypass vulnerability ↗
- ·Both on-premises Cisco APIC and cloud-hosted Cloud APIC are affected; scope detection and patching efforts to cover both deployment types ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-246h-5xw7-rvcg: A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Cont
ghsa_unreviewed·2022-05-24
CVE-2021-1579 [HIGH] CWE-269 GHSA-246h-5xw7-rvcg: A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Cont
A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Controller (Cloud APIC) could allow an authenticated, remote attacker with Administrator read-only credentials to elevate privileges on an affected system. This vulnerability is due to an insufficient role-based access control (RBAC). An attacker with Administrator read-only credentials could exploit this vulnerability by sending a specific API request using an app with admin write credentials. A successful exploit could allow the attacker to elevate privileges to Administrator with write privileges on the affected device.
Cisco
Cisco Application Policy Infrastructure Controller App Privilege Escalation Vulnerability
vendor_cisco·2021-08-25·CVSS 8.1
CVE-2021-1579 [HIGH] CWE-250 Cisco Application Policy Infrastructure Controller App Privilege Escalation Vulnerability
Cisco Application Policy Infrastructure Controller App Privilege Escalation Vulnerability
A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Controller (Cloud APIC) could allow an authenticated, remote attacker with Administrator read-only credentials to elevate privileges on an affected system.
This vulnerability is due to an insufficient role-based access control (RBAC). An attacker with Administrator read-only credentials could exploit this vulnerability by sending a specific API request using an app with admin write credentials. A successful exploit could allow the attacker to elevate privileges to Administrator with write privileges on the affected device.
Cisco has released software updat
Cisco
Cisco Application Policy Infrastructure Controller App Privilege Escalation Vulnerability
vendor_cisco·CVSS 3.1
CVE-2021-1579 Cisco Application Policy Infrastructure Controller App Privilege Escalation Vulnerability
CVE-2021-1579: Cisco Application Policy Infrastructure Controller App Privilege Escalation Vulnerability
A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Controller (Cloud APIC) could allow an authenticated, remote attacker with Administrator read-only credentials to elevate privileges on an affected system. This vulnerability is due to an insufficient role-based access control (RBAC). An attacker with Administrator read-only credentials could exploit this vulnerability by sending a specific API request using an app with admin write credentials. A successful exploit could allow the attacker to elevate privileges to Administrator with write privileges on the affected device. Cisco has released s
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-08-25
Published