Improper access control in Cisco Application Policy Infrastructure Controller and Cisco Cloud Application Policy Infrastructure Controller - CVE-2021-1581

 

Improper access control in Cisco Application Policy Infrastructure Controller and Cisco Cloud Application Policy Infrastructure Controller - CVE-2021-1581

Published: August 26, 2021


Vulnerability identifier: #VU56110
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1581
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions in an API endpoint. A remote attacker can use a specific API endpoint to upload files and fill the upload partition of the affected device.


Affected software

Cisco Application Policy Infrastructure Controller
Cisco Cloud Application Policy Infrastructure Controller

How to mitigate CVE-2021-1581

Install updates from vendor's website.

Cisco Application Policy Infrastructure Controller - addressed in versions 3.2.10f, 4.2.7l, 5.2.1g
Cisco Cloud Application Policy Infrastructure Controller - addressed in versions 3.2.10f, 4.2.7l, 5.2.1g

External References

Related Security Bulletins