QID 316930

Date Published: 2021-04-15

QID 316930: Cisco Application Policy Infrastructure Controller Out Of Band Management IP Tables Bypass Vulnerability(cisco-sa-iptable-bypass-GxW88XjL)

Affected Versions:
Cisco APIC releases prior to the first fixed software Release 4.2(3j)

QID Detection Logic (Authenticated):
The check matches Cisco APIC version retrieved via Unix Auth using "show version" command.

A vulnerability in the out of band (OOB) management interface IP table rule programming for Cisco Application Policy Infrastructure Controller (APIC) could allow an unauthenticated, remote attacker to bypass configured deny entries for specific IP ports.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Customers are advised to refer to cisco-sa-iptable-bypass-GxW88XjL for more information.

    CVEs related to QID 316930

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-iptable-bypass-GxW88XjL URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iptable-bypass-GxW88XjL