CVE-2021-1579
A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Controller (Cloud APIC) could allow an authenticated, remote attacker with Administrator read-only credentials to elevate privileges on an affected system. This vulnerability is due to an insufficient role-based access control (RBAC). An attacker with Administrator read-only credentials could exploit this vulnerability by sending a specific API request using an app with admin write credentials. A successful exploit could allow the attacker to elevate privileges to Administrator with write privileges on the affected device.
EPSS 0.83% · 74.9th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| cisco | cloud_application_policy_infrastructure_controller | 4.0, 5.0, 0 |
| Cisco | Cisco Application Policy Infrastructure Controller (APIC) | * |
| cisco | application_policy_infrastructure_controller | 0, 4.0, 5.0 |
Exploit Intelligence
Timeline
- Aug 25, 2021 CVE Published
- Aug 26, 2021 EPSS Score
- Oct 23, 2021 EPSS Score
- Dec 20, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 17, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Apr 16, 2022 EPSS Score
- Jun 13, 2022 EPSS Score
- Aug 11, 2022 EPSS Score
- Oct 8, 2022 EPSS Score
- Dec 5, 2022 EPSS Score
References
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxos-ngoam-dos-LTDb9Hv advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxos-mpls-oam-dos-sGO9x5GM advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-n9kaci-queue-wedge-cLDDEfKF advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-n9kaci-tcp-dos-YXukt6gM advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-capic-frw-Nt3RYxR2 advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-capic-chvul-CKfGYBh8 advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-capic-pesc-pkmGK4J advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-1579 advisory