Cisco Application Policy Infrastructure Controller vulnerabilities
35 known vulnerabilities affecting cisco/application_policy_infrastructure_controller.
Total CVEs
35
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH11MEDIUM19
Vulnerabilities
Page 2 of 2
CVE-2019-1692P4MEDIUMCVSS 5.3fixed in 4.1\(1i\)v8.3\(1\)s62019-05-03
CVE-2019-1692 [MEDIUM] CWE-200 CVE-2019-1692: A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Con
A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) Software could allow an unauthenticated, remote attacker to access sensitive system usage information. The vulnerability is due to a lack of proper data protection mechanisms for certain components in the underlying Application Centric In
nvd
CVE-2020-3333P4MEDIUMCVSS 5.3v1.1\(0c\)2020-06-03
CVE-2020-3333 [MEDIUM] CWE-306 CVE-2020-3333: A vulnerability in the API of Cisco Application Services Engine Software could allow an unauthentica
A vulnerability in the API of Cisco Application Services Engine Software could allow an unauthenticated, remote attacker to update event policies on an affected device. The vulnerability is due to insufficient authentication of users who modify policies on an affected device. An attacker could exploit this vulnerability by crafting a malicious HTTP re
nvd
CVE-2023-20230P4MEDIUMCVSS 5.4≥ 5.2, < 5.2\(8d\)≥ 6.0, < 6.0\(3d\)2023-08-23
CVE-2023-20230 [MEDIUM] CWE-284 CVE-2023-20230: A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrast
A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to read, modify, or delete non-tenant policies (for example, access policies) created by users associated with a different security domain on an affected system.
This vulnerabilit
nvd
CVE-2020-3139P4MEDIUMCVSS 5.3fixed in 4.2\(3j\)2020-01-26
CVE-2020-3139 [MEDIUM] CWE-20 CVE-2020-3139: A vulnerability in the out of band (OOB) management interface IP table rule programming for Cisco Ap
A vulnerability in the out of band (OOB) management interface IP table rule programming for Cisco Application Policy Infrastructure Controller (APIC) could allow an unauthenticated, remote attacker to bypass configured deny entries for specific IP ports. These IP ports would be permitted to the OOB management interface when, in fact, the packets should
nvd
CVE-2025-20119P4MEDIUMCVSS 5.7v3.2\(1l\)v3.2\(1m\)+126 more2025-02-26
CVE-2025-20119 [MEDIUM] CWE-362 CVE-2025-20119: A vulnerability in the system file permission handling of Cisco APIC could allow an authenticated, l
A vulnerability in the system file permission handling of Cisco APIC could allow an authenticated, local attacker to overwrite critical system files, which could cause a DoS condition. To exploit this vulnerability, the attacker must have valid administrative credentials.
This vulnerability is due to a race condition with handling system files. An
nvd
CVE-2015-6424P4HIGHCVSS 7.2v1.1\(0.920a\)2015-12-18
CVE-2015-6424 [HIGH] CWE-255 CVE-2015-6424: The boot manager in Cisco Application Policy Infrastructure Controller (APIC) 1.1(0.920a) allows loc
The boot manager in Cisco Application Policy Infrastructure Controller (APIC) 1.1(0.920a) allows local users to bypass intended access restrictions and obtain single-user-mode root access via unspecified vectors, aka Bug ID CSCuu83985.
nvd
CVE-2016-6457P4MEDIUMCVSS 6.5v1.2\(2\)v1.2\(3\)+3 more2016-11-19
CVE-2016-6457 [MEDIUM] CWE-119 CVE-2016-6457: A vulnerability in the Cisco Nexus 9000 Series Platform Leaf Switches for Application Centric Infras
A vulnerability in the Cisco Nexus 9000 Series Platform Leaf Switches for Application Centric Infrastructure (ACI) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability affects Cisco Nexus 9000 Series Leaf Switches (TOR) - ACI Mode and Cisco Application Policy Infrastr
nvd
CVE-2019-1838P4MEDIUMCVSS 5.4v3.2\(5d\)v4.0\(3d\)2019-05-03
CVE-2019-1838 [MEDIUM] CWE-79 CVE-2019-1838: A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Con
A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied i
nvd
CVE-2021-1582P4MEDIUMCVSS 5.4fixed in 3.2\(10f\)≥ 4.0, < 4.2\(7i\)+1 more2021-08-25
CVE-2021-1582 [MEDIUM] CWE-79 CVE-2021-1582: A vulnerability in the web UI of Cisco Application Policy Infrastructure Controller (APIC) or Cisco
A vulnerability in the web UI of Cisco Application Policy Infrastructure Controller (APIC) or Cisco Cloud APIC could allow an authenticated, remote attacker to perform a stored cross-site scripting attack on an affected system. This vulnerability is due to improper input validation in the web UI. An authenticated attacker could exploit this vulnerabilit
nvd
CVE-2020-3335P4MEDIUMCVSS 5.5v1.1\(0c\)2020-06-03
CVE-2020-3335 [MEDIUM] CWE-306 CVE-2020-3335: A vulnerability in the key store of Cisco Application Services Engine Software could allow an authen
A vulnerability in the key store of Cisco Application Services Engine Software could allow an authenticated, local attacker to read sensitive information of other users on an affected device. The vulnerability is due to insufficient authorization limitations. An attacker could exploit this vulnerability by logging in to an affected device locally with
nvd
CVE-2025-20116P4MEDIUMCVSS 4.8v3.2\(1l\)v3.2\(1m\)+126 more2025-02-26
CVE-2025-20116 [MEDIUM] CWE-79 CVE-2025-20116: A vulnerability in the web UI of Cisco APIC could allow an authenticated, remote attacker to perform
A vulnerability in the web UI of Cisco APIC could allow an authenticated, remote attacker to perform a stored XSS attack on an affected system. To exploit this vulnerability, the attacker must have valid administrative credentials.
This vulnerability is due to improper input validation in the web UI. An authenticated attacker could exploit this vuln
nvd
CVE-2024-20279P4MEDIUMCVSS 4.3v1.1\(1d\)v1.1\(1j\)+219 more2024-08-28
CVE-2024-20279 [MEDIUM] CWE-284 CVE-2024-20279: A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrast
A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to modify the behavior of default system policies, such as quality of service (QoS) policies, on an affected system. This vulnerability is due to improper access control when rest
nvd
CVE-2025-20118P4MEDIUMCVSS 4.4v3.2\(1l\)v3.2\(1m\)+126 more2025-02-26
CVE-2025-20118 [MEDIUM] CWE-212 CVE-2025-20118: A vulnerability in the implementation of the internal system processes of Cisco APIC could allow an
A vulnerability in the implementation of the internal system processes of Cisco APIC could allow an authenticated, local attacker to access sensitive information on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials.
This vulnerability is due to insufficient masking of sensitive information tha
nvd
CVE-2019-1586P4MEDIUMCVSS 4.6v4.1\(0.90a\)2019-05-03
CVE-2019-1586 [MEDIUM] CWE-320 CVE-2019-1586: A vulnerability in Cisco Application Policy Infrastructure Controller (APIC) Software could allow an
A vulnerability in Cisco Application Policy Infrastructure Controller (APIC) Software could allow an unauthenticated, local attacker with physical access to obtain sensitive information from an affected device. The vulnerability is due to insecure removal of cleartext encryption keys stored on local partitions in the hard drive of an affected device.
nvd
CVE-2015-6333P4MEDIUMCVSS 4.6v1.1\(1j\)2015-10-16
CVE-2015-6333 [MEDIUM] CWE-264 CVE-2015-6333: Cisco Application Policy Infrastructure Controller (APIC) 1.1j allows local users to gain privileges
Cisco Application Policy Infrastructure Controller (APIC) 1.1j allows local users to gain privileges via vectors involving addition of an SSH key, aka Bug ID CSCuw46076.
nvd
← Previous2 / 2