Permissions, Privileges, and Access Controls in Cisco Application Policy Infrastructure Controller and Cisco Cloud Application Policy Infrastructure Controller - CVE-2021-1578
Published: August 26, 2021
Vulnerability identifier: #VU56108
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1578
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to an improper policy default setting. A remote authenticated attacker can send a specific API request and obtain Administrator credentials on the target device.
Affected software
Cisco Application Policy Infrastructure Controller
Cisco Cloud Application Policy Infrastructure Controller
Cisco Cloud Application Policy Infrastructure Controller
How to mitigate CVE-2021-1578
Install updates from vendor's website.
Cisco Application Policy Infrastructure Controller - update to 5.1.3e
Cisco Cloud Application Policy Infrastructure Controller - update to 5.1.3e
Cisco Cloud Application Policy Infrastructure Controller - update to 5.1.3e