Cisco Aci Multi-Site Orchestrator vulnerabilities
2 known vulnerabilities affecting cisco/aci_multi-site_orchestrator.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1
Vulnerabilities
Page 1 of 1
CVE-2022-20921HIGHCVSS 8.8fixed in 3.1\(1n\)2022-08-25
CVE-2022-20921 [HIGH] CWE-285 CVE-2022-20921: A vulnerability in the API implementation of Cisco ACI Multi-Site Orchestrator (MSO) could allow an
A vulnerability in the API implementation of Cisco ACI Multi-Site Orchestrator (MSO) could allow an authenticated, remote attacker to elevate privileges on an affected device. This vulnerability is due to improper authorization on specific APIs. An attacker could exploit this vulnerability by sending crafted HTTP requests. A successful exploit could al
nvd
CVE-2021-1388CRITICALCVSS 10.0≥ 3.0, < 3.0\(3m\)2021-02-24
CVE-2021-1388 [CRITICAL] CWE-269 CVE-2021-1388: A vulnerability in an API endpoint of Cisco ACI Multi-Site Orchestrator (MSO) installed on the Appli
A vulnerability in an API endpoint of Cisco ACI Multi-Site Orchestrator (MSO) installed on the Application Services Engine could allow an unauthenticated, remote attacker to bypass authentication on an affected device. The vulnerability is due to improper token validation on a specific API endpoint. An attacker could exploit this vulnerability by se
nvd