CVE Vulnerabilities

CVE-2021-1578

Not Failing Securely ('Failing Open')

Published: Aug 25, 2021 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
9 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Controller (Cloud APIC) could allow an authenticated, remote attacker to elevate privileges to Administrator on an affected device. This vulnerability is due to an improper policy default setting. An attacker could exploit this vulnerability by using a non-privileged credential for Cisco ACI Multi-Site Orchestrator (MSO) to send a specific API request to a managed Cisco APIC or Cloud APIC device. A successful exploit could allow the attacker to obtain Administrator credentials on the affected device.

Weakness

When the product encounters an error condition or failure, its design requires it to fall back to a state that is less secure than other options that are available, such as selecting the weakest encryption algorithm or using the most permissive access control restrictions.

Affected Software

Name Vendor Start Version End Version
Application_policy_infrastructure_controller Cisco 5.0 (including) 5.1(3e) (including)
Application_policy_infrastructure_controller Cisco 5.0(2h) (including) 5.0(2h) (including)
Cloud_application_policy_infrastructure_controller Cisco 5.0 (including) 5.1(3e) (including)
Cloud_application_policy_infrastructure_controller Cisco 5.0(2h) (including) 5.0(2h) (including)

Potential Mitigations

References