PT-2021-4956 · Cisco · Cisco Apic+2

Published

2021-08-25

·

Updated

2021-09-01

·

CVE-2021-1578

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Controller (Cloud APIC) (affected versions not specified)
Description A vulnerability in the API endpoint of the affected devices could allow an authenticated, remote attacker to elevate privileges to Administrator. This issue is due to an improper policy default setting. An attacker could exploit this by sending a specific API request to a managed device using non-privileged credentials for Cisco ACI Multi-Site Orchestrator (MSO). A successful exploit could allow the attacker to obtain Administrator credentials on the affected device.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Handling of Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-05710
CVE-2021-1578

Affected Products

Cisco Aci Multi-Site Orchestrator
Cisco Apic
Cisco Cloud Apic