Vulnerabilities > Cisco > Application Policy Infrastructure Controller > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-08-23 CVE-2023-20230 Incorrect Permission Assignment for Critical Resource vulnerability in Cisco Application Policy Infrastructure Controller 5.2(1G)
A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to read, modify, or delete non-tenant policies (for example, access policies) created by users associated with a different security domain on an affected system. This vulnerability is due to improper access control when restricted security domains are used to implement multi-tenancy for policies outside the tenant boundaries.
network
low complexity
cisco CWE-732
5.4
2021-08-25 CVE-2021-1582 Cross-site Scripting vulnerability in Cisco Application Policy Infrastructure Controller
A vulnerability in the web UI of Cisco Application Policy Infrastructure Controller (APIC) or Cisco Cloud APIC could allow an authenticated, remote attacker to perform a stored cross-site scripting attack on an affected system.
network
low complexity
cisco CWE-79
5.4
2021-02-24 CVE-2021-1396 Missing Authentication for Critical Function vulnerability in Cisco products
Multiple vulnerabilities in Cisco Application Services Engine could allow an unauthenticated, remote attacker to gain privileged access to host-level operations or to learn device-specific information, create diagnostic files, and make limited configuration changes.
network
low complexity
cisco CWE-306
6.5
2020-06-03 CVE-2020-3335 Incorrect Authorization vulnerability in Cisco products
A vulnerability in the key store of Cisco Application Services Engine Software could allow an authenticated, local attacker to read sensitive information of other users on an affected device.
local
low complexity
cisco CWE-863
5.5
2020-06-03 CVE-2020-3333 Missing Authentication for Critical Function vulnerability in Cisco products
A vulnerability in the API of Cisco Application Services Engine Software could allow an unauthenticated, remote attacker to update event policies on an affected device.
network
low complexity
cisco CWE-306
5.3
2020-01-26 CVE-2020-3139 Improper Input Validation vulnerability in Cisco Application Policy Infrastructure Controller
A vulnerability in the out of band (OOB) management interface IP table rule programming for Cisco Application Policy Infrastructure Controller (APIC) could allow an unauthenticated, remote attacker to bypass configured deny entries for specific IP ports.
network
low complexity
cisco CWE-20
5.3
2019-07-04 CVE-2019-1890 Unspecified vulnerability in Cisco Application Policy Infrastructure Controller 7.3(0)Zn(0.113)
A vulnerability in the fabric infrastructure VLAN connection establishment of the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an unauthenticated, adjacent attacker to bypass security validations and connect an unauthorized server to the infrastructure VLAN.
low complexity
cisco
6.5
2019-05-03 CVE-2019-1838 Cross-site Scripting vulnerability in Cisco Application Policy Infrastructure Controller 3.2(5D)/4.0(3D)
A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device.
network
low complexity
cisco CWE-79
5.4
2019-05-03 CVE-2019-1692 Missing Encryption of Sensitive Data vulnerability in Cisco Application Policy Infrastructure Controller
A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) Software could allow an unauthenticated, remote attacker to access sensitive system usage information.
network
low complexity
cisco CWE-311
5.3
2019-05-03 CVE-2019-1586 Incomplete Cleanup vulnerability in Cisco Application Policy Infrastructure Controller 4.1(0.90A)
A vulnerability in Cisco Application Policy Infrastructure Controller (APIC) Software could allow an unauthenticated, local attacker with physical access to obtain sensitive information from an affected device.
low complexity
cisco CWE-459
4.6