QID 316937
Date Published: 2021-04-19
QID 316937: Cisco Application Policy Infrastructure Controller SSH Privilege Escalation Vulnerability(cisco-sa-20170816-apic1,cisco-sa-20170816-apic2)
Affected Versions:
Cisco Application Policy Infrastructure Controller Version 2.2(2e) and 2.3 prior to 2.3(1f)
QID Detection Logic (Authenticated):
The check matches Cisco APIC version retrieved via Unix Auth using "show version" command.
A vulnerability in Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to gain higher privileges than the account is assigned.
Solution
Customers are advised to refer to cisco-sa-20170816-apic1 for more information.
Vendor References
- cisco-sa-20170816-apic1 -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170816-apic1 - cisco-sa-20170816-apic2 -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170816-apic2
CVEs related to QID 316937
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-20170816-apic1 |
|