Execution with unnecessary privileges in Cisco Application Policy Infrastructure Controller and Cisco Cloud Application Policy Infrastructure Controller - CVE-2021-1579

 

Execution with unnecessary privileges in Cisco Application Policy Infrastructure Controller and Cisco Cloud Application Policy Infrastructure Controller - CVE-2021-1579

Published: August 26, 2021


Vulnerability identifier: #VU56112
CSH Severity: Medium
CVSS v4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1579
CWE-ID: CWE-250
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due to an insufficient role-based access control (RBAC). A remote authenticated attacker can send a specially crafted API request and elevate privileges to Administrator with write privileges on the affected device.


Affected software

Cisco Application Policy Infrastructure Controller
Cisco Cloud Application Policy Infrastructure Controller

How to mitigate CVE-2021-1579

Install updates from vendor's website.

Cisco Application Policy Infrastructure Controller - addressed in versions 3.2.10f, 4.2.7l, 5.2.2f
Cisco Cloud Application Policy Infrastructure Controller - addressed in versions 3.2.10f, 4.2.7l, 5.2.2f

External References

Related Security Bulletins