QID 316940
Date Published: 2021-04-19
QID 316940: Cisco Application Policy Infrastructure Controller Insecure Credentials Vulnerability(cisco-sa-20151216-apic)
Affected Versions:
Cisco Application Policy Infrastructure Controller Version 1.1(0.920a)
QID Detection Logic (Authenticated):
The check matches Cisco APIC version retrieved via Unix Auth using "show version" command.
A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device.
Solution
Customers are advised to refer to cisco-sa-20151216-apic for more information.
Vendor References
- cisco-sa-20151216-apic -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151216-apic
CVEs related to QID 316940
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-20151216-apic |
|