QID 316932

Date Published: 2021-04-19

QID 316932: Cisco Application Policy Infrastructure Controller Web-Based Management Interface Usage Information Disclosure Vulnerability(cisco-sa-20190501-apic-info-disc)

Affected Versions:
Cisco Application Policy Infrastructure Controller Version 4.1(0.88a) and 8.3(1)S6

QID Detection Logic (Authenticated):
The check matches Cisco APIC version retrieved via Unix Auth using "show version" command.

A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) Software could allow an unauthenticated, remote attacker to access sensitive system usage information.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Customers are advised to refer to cisco-sa-20190501-apic-info-disc for more information.

    CVEs related to QID 316932

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-20190501-apic-info-disc URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190501-apic-info-disc