Home/Product/cisco application policy infrastructure controller
Product

cisco application policy infrastructure controller

34 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-20119
all versions
A vulnerability in the system file permission handling of Cisco APIC could allow an authenticated, local attacker to overwrite cri
6.0MEDIUM
CVE-2025-20118
all versions
A vulnerability in the implementation of the internal system processes of Cisco APIC could allow an authenticated, local attacker
4.4MEDIUM
CVE-2025-20117
all versions
A vulnerability in the CLI of Cisco APIC could allow an authenticated, local attacker to execute arbitrary commands as root o
5.1MEDIUM
CVE-2025-20116
all versions
A vulnerability in the web UI of Cisco APIC could allow an authenticated, remote attacker to perform a stored XSS attack on an aff
4.8MEDIUM
CVE-2024-20478
all versions
A vulnerability in the software upgrade component of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Clou
6.5MEDIUM
CVE-2024-20279
all versions
A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (APIC) coul
4.3MEDIUM
CVE-2023-20230
>= 5.2 and < 5.2\(8d\)
A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (APIC) coul
5.4MEDIUM
CVE-2023-20011
>= 4.2\(6\) and < 5.2\(7g\)
A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud
8.8HIGH
CVE-2021-1582
< 3.2\(10f\)
A vulnerability in the web UI of Cisco Application Policy Infrastructure Controller (APIC) or Cisco Cloud APIC could allow an auth
5.4MEDIUM
CVE-2021-1581
< 3.2\(10f\)
Multiple vulnerabilities in the web UI and API endpoints of Cisco Application Policy Infrastructure Controller (APIC) or Cisco Clo
6.5MEDIUM
CVE-2021-1580
< 3.2\(10e\)
Multiple vulnerabilities in the web UI and API endpoints of Cisco Application Policy Infrastructure Controller (APIC) or Cisco Clo
6.5MEDIUM
CVE-2021-1579
< 3.2\(10f\)
A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy
8.1HIGH
CVE-2021-1578
>= 5.0 and <= 5.1\(3e\)
A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy
8.8HIGH
CVE-2021-1577
< 3.2\(10e\)
A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy
9.1CRITICAL
CVE-2021-1396
all versions
Multiple vulnerabilities in Cisco Application Services Engine could allow an unauthenticated, remote attacker to gain privileged a
9.8CRITICAL
CVE-2021-1393
all versions
Multiple vulnerabilities in Cisco Application Services Engine could allow an unauthenticated, remote attacker to gain privileged a
9.8CRITICAL
CVE-2021-1388
all versions
A vulnerability in an API endpoint of Cisco ACI Multi-Site Orchestrator (MSO) installed on the Application Services Engine could a
10.0CRITICAL
CVE-2020-3335
all versions
A vulnerability in the key store of Cisco Application Services Engine Software could allow an authenticated, local attacker to rea
5.5MEDIUM
CVE-2020-3333
all versions
A vulnerability in the API of Cisco Application Services Engine Software could allow an unauthenticated, remote attacker to update
5.3MEDIUM
CVE-2020-3139
< 4.2\(3j\)
A vulnerability in the out of band (OOB) management interface IP table rule programming for Cisco Application Policy Infrastructur
5.3MEDIUM
CVE-2019-1890
all versions
A vulnerability in the fabric infrastructure VLAN connection establishment of the Cisco Nexus 9000 Series Application Centric Infr
6.5MEDIUM
CVE-2019-1889
all versions
A vulnerability in the REST API for software device management in Cisco Application Policy Infrastructure Controller (APIC) Softwa
7.2HIGH
CVE-2019-1838
all versions
A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) could allow an
5.4MEDIUM
CVE-2019-1692
< 4.1\(1i\)
A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) Software could
5.3MEDIUM
CVE-2019-1682
< 4.1\(1i\)
A vulnerability in the FUSE filesystem functionality for Cisco Application Policy Infrastructure Controller (APIC) software could
7.8HIGH
CVE-2019-1586
all versions
A vulnerability in Cisco Application Policy Infrastructure Controller (APIC) Software could allow an unauthenticated, local attack
4.6MEDIUM
CVE-2019-1690
< 4.2\(0.21c\)
A vulnerability in the management interface of Cisco Application Policy Infrastructure Controller (APIC) software could allow an u
6.5MEDIUM
CVE-2017-12352
all versions
A vulnerability in certain system script files that are installed at boot time on Cisco Application Policy Infrastructure Controll
6.7MEDIUM
CVE-2017-6768
all versions
A vulnerability in the build procedure for certain executable system files installed at boot time on Cisco Application Policy Infr
7.8HIGH
CVE-2017-6767
all versions
A vulnerability in Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to gain
7.1HIGH
CVE-2016-6457
all versions
A vulnerability in the Cisco Nexus 9000 Series Platform Leaf Switches for Application Centric Infrastructure (ACI) could allow an
6.5MEDIUM
CVE-2016-6413
all versions
The installation procedure on Cisco Application Policy Infrastructure Controller (APIC) devices 1.3(2f) mishandles binary files, w
7.8HIGH
CVE-2015-6424
all versions
The boot manager in Cisco Application Policy Infrastructure Controller (APIC) 1.1(0.920a) allows local users to bypass intended ac
CVE-2015-6333
all versions
Cisco Application Policy Infrastructure Controller (APIC) 1.1j allows local users to gain privileges via vectors involving additio
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin