CVE Vulnerabilities

CVE-2021-1581

Published: Aug 25, 2021 | Modified: Nov 07, 2023
CVSS 3.x
9.1
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Multiple vulnerabilities in the web UI and API endpoints of Cisco Application Policy Infrastructure Controller (APIC) or Cisco Cloud APIC could allow a remote attacker to perform a command injection or file upload attack on an affected system. For more information about these vulnerabilities, see the Details section of this advisory.

Affected Software

Name Vendor Start Version End Version
Application_policy_infrastructure_controller Cisco * 3.2(10f) (excluding)
Application_policy_infrastructure_controller Cisco 4.0 (including) 4.2(7l) (excluding)
Application_policy_infrastructure_controller Cisco 5.0 (including) 5.2(1g) (excluding)
Cloud_application_policy_infrastructure_controller Cisco * 3.2(10f) (excluding)
Cloud_application_policy_infrastructure_controller Cisco 4.0 (including) 4.2(7l) (excluding)
Cloud_application_policy_infrastructure_controller Cisco 5.0 (including) 5.2(1g) (excluding)

References