PT-2021-4956 · Cisco · Cisco Apic+2
Published
2021-08-25
·
Updated
2021-09-01
·
CVE-2021-1578
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Controller (Cloud APIC) (affected versions not specified)
Description
A vulnerability in the API endpoint of the affected devices could allow an authenticated, remote attacker to elevate privileges to Administrator. This issue is due to an improper policy default setting. An attacker could exploit this by sending a specific API request to a managed device using non-privileged credentials for Cisco ACI Multi-Site Orchestrator (MSO). A successful exploit could allow the attacker to obtain Administrator credentials on the affected device.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Handling of Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Aci Multi-Site Orchestrator
Cisco Apic
Cisco Cloud Apic