Cisco Application Policy Infrastructure Controller vulnerabilities
35 known vulnerabilities affecting cisco/application_policy_infrastructure_controller.
Total CVEs
35
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH11MEDIUM19
Vulnerabilities
Page 1 of 2
CVE-2021-1388P1CRITICALCVSS 10.0v3.0\(3i\)2021-02-24
CVE-2021-1388 [CRITICAL] CWE-269 CVE-2021-1388: A vulnerability in an API endpoint of Cisco ACI Multi-Site Orchestrator (MSO) installed on the Appli
A vulnerability in an API endpoint of Cisco ACI Multi-Site Orchestrator (MSO) installed on the Application Services Engine could allow an unauthenticated, remote attacker to bypass authentication on an affected device. The vulnerability is due to improper token validation on a specific API endpoint. An attacker could exploit this vulnerability by se
nvd
CVE-2021-1577P2CRITICALCVSS 9.1fixed in 3.2\(10e\)≥ 4.0, < 4.2\(6h\)+1 more2021-08-25
CVE-2021-1577 [CRITICAL] CWE-284 CVE-2021-1577: A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and
A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Controller (Cloud APIC) could allow an unauthenticated, remote attacker to read or write arbitrary files on an affected system. This vulnerability is due to improper access control. An attacker could exploi
nvd
CVE-2021-1393P2CRITICALCVSS 9.8v1.1.32021-02-24
CVE-2021-1393 [CRITICAL] CWE-306 CVE-2021-1393: Multiple vulnerabilities in Cisco Application Services Engine could allow an unauthenticated, remote
Multiple vulnerabilities in Cisco Application Services Engine could allow an unauthenticated, remote attacker to gain privileged access to host-level operations or to learn device-specific information, create diagnostic files, and make limited configuration changes. For more information about these vulnerabilities, see the Details section of this ad
nvd
CVE-2021-1579P2HIGHCVSS 8.8fixed in 3.2\(10f\)≥ 4.0, < 4.2\(7l\)+1 more2021-08-25
CVE-2021-1579 [HIGH] CWE-250 CVE-2021-1579: A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and
A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Controller (Cloud APIC) could allow an authenticated, remote attacker with Administrator read-only credentials to elevate privileges on an affected system. This vulnerability is due to an insufficient role-base
nvd
CVE-2021-1578P2HIGHCVSS 8.8≥ 5.0, ≤ 5.1\(3e\)v5.0\(2h\)2021-08-25
CVE-2021-1578 [HIGH] CWE-636 CVE-2021-1578: A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and
A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Controller (Cloud APIC) could allow an authenticated, remote attacker to elevate privileges to Administrator on an affected device. This vulnerability is due to an improper policy default setting. An attacker c
nvd
CVE-2021-1581P3CRITICALCVSS 9.1fixed in 3.2\(10f\)≥ 4.0, < 4.2\(7l\)+1 more2021-08-25
CVE-2021-1581 [CRITICAL] CWE-284 CVE-2021-1581: Multiple vulnerabilities in the web UI and API endpoints of Cisco Application Policy Infrastructure
Multiple vulnerabilities in the web UI and API endpoints of Cisco Application Policy Infrastructure Controller (APIC) or Cisco Cloud APIC could allow a remote attacker to perform a command injection or file upload attack on an affected system. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2024-20478P3HIGHCVSS 7.2v1.1\(1d\)v1.1\(1j\)+220 more2024-08-28
CVE-2024-20478 [HIGH] CWE-250 CVE-2024-20478: A vulnerability in the software upgrade component of Cisco Application Policy Infrastructure Control
A vulnerability in the software upgrade component of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Network Controller, formerly Cisco Cloud APIC, could allow an authenticated, remote attacker with Administrator-level privileges to install a modified software image, leading to arbitrary code injection on an affected system.
nvd
CVE-2023-20011P3HIGHCVSS 8.8≥ 4.2\(6\), < 5.2\(7g\)≥ 6.0, < 6.0\(2h\)2023-02-23
CVE-2023-20011 [HIGH] CWE-352 CVE-2023-20011: A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Con
A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Network Controller, formerly Cisco Cloud APIC, could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF pro
nvd
CVE-2019-1889P3HIGHCVSS 7.2v4.1\(1j\)2019-07-04
CVE-2019-1889 [HIGH] CWE-264 CVE-2019-1889: A vulnerability in the REST API for software device management in Cisco Application Policy Infrastru
A vulnerability in the REST API for software device management in Cisco Application Policy Infrastructure Controller (APIC) Software could allow an authenticated, remote attacker to escalate privileges to root on an affected device. The vulnerability is due to incomplete validation and error checking for the file path when specific software is uploaded.
nvd
CVE-2015-4235P3CRITICALCVSS 9.0v1.0\(1e\)2015-07-24
CVE-2015-4235 [CRITICAL] CWE-264 CVE-2015-4235: Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.0(3o) and 1
Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.0(3o) and 1.1 before 1.1(1j) and Nexus 9000 ACI devices with software before 11.0(4o) and 11.1 before 11.1(1j) do not properly restrict access to the APIC filesystem, which allows remote authenticated users to obtain root privileges via unspecified use of the AP
nvd
CVE-2021-1580P3HIGHCVSS 7.2fixed in 3.2\(10e\)≥ 4.0, < 4.2\(6h\)+1 more2021-08-25
CVE-2021-1580 [HIGH] CWE-284 CVE-2021-1580: Multiple vulnerabilities in the web UI and API endpoints of Cisco Application Policy Infrastructure
Multiple vulnerabilities in the web UI and API endpoints of Cisco Application Policy Infrastructure Controller (APIC) or Cisco Cloud APIC could allow a remote attacker to perform a command injection or file upload attack on an affected system. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2019-1682P3HIGHCVSS 7.8fixed in 4.1\(1i\)2019-05-03
CVE-2019-1682 [HIGH] CWE-264 CVE-2019-1682: A vulnerability in the FUSE filesystem functionality for Cisco Application Policy Infrastructure Con
A vulnerability in the FUSE filesystem functionality for Cisco Application Policy Infrastructure Controller (APIC) software could allow an authenticated, local attacker to escalate privileges to root on an affected device. The vulnerability is due to insufficient input validation for certain command strings issued on the CLI of the affected device. An a
nvd
CVE-2017-6768P3HIGHCVSS 7.8v1.1\(0.920a\)v1.1\(1j\)+10 more2017-08-17
CVE-2017-6768 [HIGH] CWE-426 CVE-2017-6768: A vulnerability in the build procedure for certain executable system files installed at boot time on
A vulnerability in the build procedure for certain executable system files installed at boot time on Cisco Application Policy Infrastructure Controller (APIC) devices could allow an authenticated, local attacker to gain root-level privileges. The vulnerability is due to a custom executable system file that was built to use relative search paths for libr
nvd
CVE-2021-1396P3MEDIUMCVSS 6.5v1.1.32021-02-24
CVE-2021-1396 [MEDIUM] CWE-306 CVE-2021-1396: Multiple vulnerabilities in Cisco Application Services Engine could allow an unauthenticated, remote
Multiple vulnerabilities in Cisco Application Services Engine could allow an unauthenticated, remote attacker to gain privileged access to host-level operations or to learn device-specific information, create diagnostic files, and make limited configuration changes. For more information about these vulnerabilities, see the Details section of this advi
nvd
CVE-2025-20117P3MEDIUMCVSS 6.7v3.2\(1l\)v3.2\(1m\)+126 more2025-02-26
CVE-2025-20117 [MEDIUM] CWE-77 CVE-2025-20117: A vulnerability in the CLI of Cisco APIC could allow an authenticated, local attacker to execute arb
A vulnerability in the CLI of Cisco APIC could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials.
This vulnerability is due to insufficient validation of arguments that are passed
nvd
CVE-2016-6413P3HIGHCVSS 7.8v1.3\(2f\)2016-09-24
CVE-2016-6413 [HIGH] CWE-264 CVE-2016-6413: The installation procedure on Cisco Application Policy Infrastructure Controller (APIC) devices 1.3(
The installation procedure on Cisco Application Policy Infrastructure Controller (APIC) devices 1.3(2f) mishandles binary files, which allows local users to obtain root access via unspecified vectors, aka Bug ID CSCva50496.
nvd
CVE-2017-6767P3HIGHCVSS 7.1v1.0\(1e\)v1.0\(1h\)+22 more2017-08-17
CVE-2017-6767 [HIGH] CWE-269 CVE-2017-6767: A vulnerability in Cisco Application Policy Infrastructure Controller (APIC) could allow an authenti
A vulnerability in Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to gain higher privileges than the account is assigned. The attacker will be granted the privileges of the last user to log in, regardless of whether those privileges are higher or lower than what should have been granted. The attac
nvd
CVE-2017-12352P4MEDIUMCVSS 6.7v2.3\(1f\)2017-11-30
CVE-2017-12352 [MEDIUM] CWE-77 CVE-2017-12352: A vulnerability in certain system script files that are installed at boot time on Cisco Application
A vulnerability in certain system script files that are installed at boot time on Cisco Application Policy Infrastructure Controllers could allow an authenticated, local attacker to gain elevated privileges and execute arbitrary commands with root privileges on an affected host operating system. The vulnerability is due to insufficient validation of u
nvd
CVE-2019-1890P4MEDIUMCVSS 6.5v7.3\(0\)zn\(0.113\)2019-07-04
CVE-2019-1890 [MEDIUM] CWE-284 CVE-2019-1890: A vulnerability in the fabric infrastructure VLAN connection establishment of the Cisco Nexus 9000 S
A vulnerability in the fabric infrastructure VLAN connection establishment of the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an unauthenticated, adjacent attacker to bypass security validations and connect an unauthorized server to the infrastructure VLAN. The vulnerability is due to insufficient
nvd
CVE-2019-1690P4MEDIUMCVSS 6.5fixed in 4.2\(0.21c\)2019-03-11
CVE-2019-1690 [MEDIUM] CWE-284 CVE-2019-1690: A vulnerability in the management interface of Cisco Application Policy Infrastructure Controller (A
A vulnerability in the management interface of Cisco Application Policy Infrastructure Controller (APIC) software could allow an unauthenticated, adjacent attacker to gain unauthorized access on an affected device. The vulnerability is due to a lack of proper access control mechanisms for IPv6 link-local connectivity imposed on the management interfac
nvd
1 / 2Next →