PT-2021-5013 · Cisco · Cisco Apic+1

Adrien Peter

+2

·

Published

2021-08-25

·

Updated

2021-09-01

·

CVE-2021-1582

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cisco Application Policy Infrastructure Controller (APIC) or Cisco Cloud APIC (affected versions not specified)
Description A vulnerability in the web UI of Cisco Application Policy Infrastructure Controller (APIC) or Cisco Cloud APIC could allow an authenticated, remote attacker to perform a stored cross-site scripting attack on an affected system. This issue is due to improper input validation in the web UI. An authenticated attacker could exploit this vulnerability by sending malicious input to the web UI, potentially allowing the execution of arbitrary script code in the context of the web-based interface or access to sensitive, browser-based information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-05780
CVE-2021-1582

Affected Products

Cisco Apic
Cisco Cloud Apic