SB2017110211 - Privilege escalation in Cisco Application Policy Infrastructure Controller
Published: November 2, 2017
Security Bulletin ID
SB2017110211
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Adjecent network
Highest impact
Code execution
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Privilege escalation (CVE-ID: CVE-2017-12262)
The vulnerability allows an adjacent attacker to gain privileged access to the target device.The weakness exists within the firewall configuration of the Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) due to incorrect firewall rule. An adjacent attacker can send traffic to the public interface to be forwarded to the internal virtual network of the APIC-EM and gain access to services listening on the internal network with elevated privileges.
Remediation
Install update from vendor's website.