QID 316934

Date Published: 2021-04-19

QID 316934: Cisco Application Policy Infrastructure Controller IPv6 Link-Local Address Vulnerability(cisco-sa-20190306-apic-ipv6)

Affected Versions:
Cisco Application Policy Infrastructure Controller Version 3.2(2l) and 8.3(1)S6

QID Detection Logic (Authenticated):
The check matches Cisco APIC version retrieved via Unix Auth using "show version" command.

A vulnerability in the management interface of Cisco Application Policy Infrastructure Controller (APIC) software could allow an unauthenticated, adjacent attacker to gain unauthorized access on an affected device.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 3.3 severity.
  • Solution

    Customers are advised to refer to cisco-sa-20190306-apic-ipv6 for more information.

    CVEs related to QID 316934

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-20190306-apic-ipv6 URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190306-apic-ipv6