cbcvebase.

Cisco Application Policy Infrastructure Controller vulnerabilities

25 known vulnerabilities affecting cisco/cisco_application_policy_infrastructure_controller.

Total CVEs
25
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH7MEDIUM16

Vulnerabilities

Page 2 of 2
CVE-2024-20279P4MEDIUMCVSS 4.3v3.2(8d)v2.2(1o)+219 more2024-08-28
CVE-2024-20279 [MEDIUM] CWE-284 CVE-2024-20279: A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrast A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to modify the behavior of default system policies, such as quality of service (QoS) policies, on an affected system. This vulnerability is due to improper access control when rest
nvd
CVE-2026-20107P4MEDIUMCVSS 5.5v6.1(1f)v6.1(2f)+3 more2026-02-25
CVE-2026-20107 [MEDIUM] CWE-1220 CVE-2026-20107: A vulnerability in the Object Model CLI component of Cisco Application Policy Infrastructure Control A vulnerability in the Object Model CLI component of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, local attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. To exploit this vulnerability, the attacker must have valid user credentials and any role th
nvd
CVE-2019-1587P4MEDIUMCVSS 4.3≥ unspecified, < 4.2(0.33c)2019-05-03
CVE-2019-1587 [MEDIUM] CWE-399 CVE-2019-1587: A vulnerability in Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (AC A vulnerability in Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an authenticated, remote attacker to access sensitive information. The vulnerability occurs because the affected software does not properly validate user-supplied input. An attacker could exploit this vulnerability by issuing certain
nvd
CVE-2025-20118P4MEDIUMCVSS 4.4v3.2(8d)v3.2(1m)+126 more2025-02-26
CVE-2025-20118 [MEDIUM] CWE-212 CVE-2025-20118: A vulnerability in the implementation of the internal system processes of Cisco APIC could allow an A vulnerability in the implementation of the internal system processes of Cisco APIC could allow an authenticated, local attacker to access sensitive information on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient masking of sensitive information tha
nvd
CVE-2019-1586P4MEDIUMCVSS 4.6≥ unspecified, < 4.2(0.33c)2019-05-03
CVE-2019-1586 [MEDIUM] CWE-320 CVE-2019-1586: A vulnerability in Cisco Application Policy Infrastructure Controller (APIC) Software could allow an A vulnerability in Cisco Application Policy Infrastructure Controller (APIC) Software could allow an unauthenticated, local attacker with physical access to obtain sensitive information from an affected device. The vulnerability is due to insecure removal of cleartext encryption keys stored on local partitions in the hard drive of an affected device.
nvd
Cisco Application Policy Infrastructure Controller vulnerabilities | cvebase