Cisco
Cisco Application Policy Infrastructure Controller: vulnerabilidades y CVE
Cisco Application Policy Infrastructure Controller tiene 35 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE35
Últimos 12 meses1
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-20107 | Media (5.5) | 0.09% | — | 25 feb 2026 | A vulnerability in the Object Model CLI component of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, local attacker to cause an affected device to reload unexpectedly, resulting… |
| CVE-2025-20119 | Media (5.7) | 0.10% | — | 26 feb 2025 | A vulnerability in the system file permission handling of Cisco APIC could allow an authenticated, local attacker to overwrite critical system files, which could cause a DoS condition. To exploit this vulnerability, the… |
| CVE-2025-20118 | Media (4.4) | 0.16% | — | 26 feb 2025 | A vulnerability in the implementation of the internal system processes of Cisco APIC could allow an authenticated, local attacker to access sensitive information on an affected device. To exploit this vulnerability, the… |
| CVE-2025-20117 | Media (6.7) | 0.19% | — | 26 feb 2025 | A vulnerability in the CLI of Cisco APIC could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying operating system of an affected device. To exploit this vulnerability,… |
| CVE-2025-20116 | Media (4.8) | 0.28% | — | 26 feb 2025 | A vulnerability in the web UI of Cisco APIC could allow an authenticated, remote attacker to perform a stored XSS attack on an affected system. To exploit this vulnerability, the attacker must have valid administrative… |
| CVE-2024-20478 | Alta (7.2) | 0.74% | — | 28 ago 2024 | A vulnerability in the software upgrade component of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Network Controller, formerly Cisco Cloud APIC, could allow an authenticated, remote… |
| CVE-2024-20279 | Media (4.3) | 0.32% | — | 28 ago 2024 | A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to modify the behavior of default system… |
| CVE-2023-20230 | Media (5.4) | 0.44% | — | 23 ago 2023 | A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to read, modify, or delete non-tenant policies… |
| CVE-2023-20011 | Alta (8.8) | 0.36% | — | 23 feb 2023 | A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Network Controller, formerly Cisco Cloud APIC, could allow an unauthenticated, remote… |
| CVE-2021-1582 | Media (5.4) | 0.60% | — | 25 ago 2021 | A vulnerability in the web UI of Cisco Application Policy Infrastructure Controller (APIC) or Cisco Cloud APIC could allow an authenticated, remote attacker to perform a stored cross-site scripting attack on an affected… |
| CVE-2021-1581 | Crítica (9.1) | 1.1% | — | 25 ago 2021 | Multiple vulnerabilities in the web UI and API endpoints of Cisco Application Policy Infrastructure Controller (APIC) or Cisco Cloud APIC could allow a remote attacker to perform a command injection or file upload… |
| CVE-2021-1580 | Alta (7.2) | 1.8% | — | 25 ago 2021 | Multiple vulnerabilities in the web UI and API endpoints of Cisco Application Policy Infrastructure Controller (APIC) or Cisco Cloud APIC could allow a remote attacker to perform a command injection or file upload… |
| CVE-2021-1579 | Alta (8.8) | 2.1% | — | 25 ago 2021 | A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Controller (Cloud APIC) could allow an authenticated, remote attacker… |
| CVE-2021-1578 | Alta (8.8) | 2.0% | — | 25 ago 2021 | A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Controller (Cloud APIC) could allow an authenticated, remote attacker to… |
| CVE-2021-1577 | Crítica (9.1) | 1.3% | — | 25 ago 2021 | A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Controller (Cloud APIC) could allow an unauthenticated, remote attacker… |
| CVE-2021-1396 | Media (6.5) | 1.0% | — | 24 feb 2021 | Multiple vulnerabilities in Cisco Application Services Engine could allow an unauthenticated, remote attacker to gain privileged access to host-level operations or to learn device-specific information, create diagnostic… |
| CVE-2021-1393 | Crítica (9.8) | 2.3% | — | 24 feb 2021 | Multiple vulnerabilities in Cisco Application Services Engine could allow an unauthenticated, remote attacker to gain privileged access to host-level operations or to learn device-specific information, create diagnostic… |
| CVE-2021-1388 | Crítica (10) | 15% | — | 24 feb 2021 | A vulnerability in an API endpoint of Cisco ACI Multi-Site Orchestrator (MSO) installed on the Application Services Engine could allow an unauthenticated, remote attacker to bypass authentication on an affected device.… |
| CVE-2020-3335 | Media (5.5) | 0.29% | — | 3 jun 2020 | A vulnerability in the key store of Cisco Application Services Engine Software could allow an authenticated, local attacker to read sensitive information of other users on an affected device. The vulnerability is due to… |
| CVE-2020-3333 | Media (5.3) | 1.0% | — | 3 jun 2020 | A vulnerability in the API of Cisco Application Services Engine Software could allow an unauthenticated, remote attacker to update event policies on an affected device. The vulnerability is due to insufficient… |
| CVE-2020-3139 | Media (5.3) | 1.0% | — | 26 ene 2020 | A vulnerability in the out of band (OOB) management interface IP table rule programming for Cisco Application Policy Infrastructure Controller (APIC) could allow an unauthenticated, remote attacker to bypass configured… |
| CVE-2019-1890 | Media (6.5) | 0.63% | — | 4 jul 2019 | A vulnerability in the fabric infrastructure VLAN connection establishment of the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an unauthenticated, adjacent attacker… |
| CVE-2019-1889 | Alta (7.2) | 2.8% | — | 4 jul 2019 | A vulnerability in the REST API for software device management in Cisco Application Policy Infrastructure Controller (APIC) Software could allow an authenticated, remote attacker to escalate privileges to root on an… |
| CVE-2019-1838 | Media (5.4) | 0.81% | — | 3 may 2019 | A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a… |
| CVE-2019-1692 | Media (5.3) | 1.2% | — | 3 may 2019 | A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) Software could allow an unauthenticated, remote attacker to access sensitive system usage information.… |
| CVE-2019-1682 | Alta (7.8) | 0.35% | — | 3 may 2019 | A vulnerability in the FUSE filesystem functionality for Cisco Application Policy Infrastructure Controller (APIC) software could allow an authenticated, local attacker to escalate privileges to root on an affected… |
| CVE-2019-1586 | Media (4.6) | 0.20% | — | 3 may 2019 | A vulnerability in Cisco Application Policy Infrastructure Controller (APIC) Software could allow an unauthenticated, local attacker with physical access to obtain sensitive information from an affected device. The… |
| CVE-2019-1690 | Media (6.5) | 0.61% | — | 11 mar 2019 | A vulnerability in the management interface of Cisco Application Policy Infrastructure Controller (APIC) software could allow an unauthenticated, adjacent attacker to gain unauthorized access on an affected device. The… |
| CVE-2017-12352 | Media (6.7) | 0.45% | — | 30 nov 2017 | A vulnerability in certain system script files that are installed at boot time on Cisco Application Policy Infrastructure Controllers could allow an authenticated, local attacker to gain elevated privileges and execute… |
| CVE-2017-6768 | Alta (7.8) | 0.42% | — | 17 ago 2017 | A vulnerability in the build procedure for certain executable system files installed at boot time on Cisco Application Policy Infrastructure Controller (APIC) devices could allow an authenticated, local attacker to gain… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.