Cisco Aci Multi-Site Orchestrator Software vulnerabilities
2 known vulnerabilities affecting cisco/cisco_aci_multi-site_orchestrator_software.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1
Vulnerabilities
Page 1 of 1
CVE-2022-20921HIGHCVSS 8.8vn/a2022-08-25
CVE-2022-20921 [HIGH] CWE-285 CVE-2022-20921: A vulnerability in the API implementation of Cisco ACI Multi-Site Orchestrator (MSO) could allow an
A vulnerability in the API implementation of Cisco ACI Multi-Site Orchestrator (MSO) could allow an authenticated, remote attacker to elevate privileges on an affected device. This vulnerability is due to improper authorization on specific APIs. An attacker could exploit this vulnerability by sending crafted HTTP requests. A successful exploit could al
cvelistv5nvd
CVE-2021-1388CRITICALCVSS 10.0vn/a2021-02-24
CVE-2021-1388 [CRITICAL] CWE-269 CVE-2021-1388: A vulnerability in an API endpoint of Cisco ACI Multi-Site Orchestrator (MSO) installed on the Appli
A vulnerability in an API endpoint of Cisco ACI Multi-Site Orchestrator (MSO) installed on the Application Services Engine could allow an unauthenticated, remote attacker to bypass authentication on an affected device. The vulnerability is due to improper token validation on a specific API endpoint. An attacker could exploit this vulnerability by se
cvelistv5nvd