Vulnerabilities > Cisco > Application Policy Infrastructure Controller

DATE CVE VULNERABILITY TITLE RISK
2019-03-11 CVE-2019-1690 Unspecified vulnerability in Cisco Application Policy Infrastructure Controller
A vulnerability in the management interface of Cisco Application Policy Infrastructure Controller (APIC) software could allow an unauthenticated, adjacent attacker to gain unauthorized access on an affected device.
low complexity
cisco
3.3
2017-11-30 CVE-2017-12352 Command Injection vulnerability in Cisco Application Policy Infrastructure Controller 2.3(1F)
A vulnerability in certain system script files that are installed at boot time on Cisco Application Policy Infrastructure Controllers could allow an authenticated, local attacker to gain elevated privileges and execute arbitrary commands with root privileges on an affected host operating system.
local
low complexity
cisco CWE-77
7.2
2017-08-17 CVE-2017-6768 Untrusted Search Path vulnerability in Cisco Application Policy Infrastructure Controller
A vulnerability in the build procedure for certain executable system files installed at boot time on Cisco Application Policy Infrastructure Controller (APIC) devices could allow an authenticated, local attacker to gain root-level privileges.
local
low complexity
cisco CWE-426
7.2
2017-08-17 CVE-2017-6767 Improper Privilege Management vulnerability in Cisco Application Policy Infrastructure Controller
A vulnerability in Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to gain higher privileges than the account is assigned.
network
high complexity
cisco CWE-269
4.6
2016-11-19 CVE-2016-6457 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco products
A vulnerability in the Cisco Nexus 9000 Series Platform Leaf Switches for Application Centric Infrastructure (ACI) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the affected device.
low complexity
cisco CWE-119
6.1
2016-09-24 CVE-2016-6413 Permissions, Privileges, and Access Controls vulnerability in Cisco Application Policy Infrastructure Controller 1.3(2F)
The installation procedure on Cisco Application Policy Infrastructure Controller (APIC) devices 1.3(2f) mishandles binary files, which allows local users to obtain root access via unspecified vectors, aka Bug ID CSCva50496.
local
low complexity
cisco CWE-264
6.8
2016-02-07 CVE-2016-1302 Improper Access Control vulnerability in Cisco products
Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.0(3h) and 1.1 before 1.1(1j) and Nexus 9000 ACI Mode switches with software before 11.0(3h) and 11.1 before 11.1(1j) allow remote authenticated users to bypass intended RBAC restrictions via crafted REST requests, aka Bug ID CSCut12998.
network
low complexity
cisco CWE-284
critical
9.0
2015-12-18 CVE-2015-6424 Credentials Management vulnerability in Cisco Application Policy Infrastructure Controller 1.1(0.920A)
The boot manager in Cisco Application Policy Infrastructure Controller (APIC) 1.1(0.920a) allows local users to bypass intended access restrictions and obtain single-user-mode root access via unspecified vectors, aka Bug ID CSCuu83985.
local
low complexity
cisco CWE-255
7.2
2015-10-16 CVE-2015-6333 Permissions, Privileges, and Access Controls vulnerability in Cisco Application Policy Infrastructure Controller 1.1(1J)
Cisco Application Policy Infrastructure Controller (APIC) 1.1j allows local users to gain privileges via vectors involving addition of an SSH key, aka Bug ID CSCuw46076.
local
low complexity
cisco CWE-264
4.6