QID 317031

Date Published: 2021-09-09

QID 317031: Cisco Application Policy Infrastructure Controller (APIC) File Upload Vulnerabilities (cisco-sa-capic-mdvul-HBsJBuvW)

Multiple vulnerabilities in the web UI and API endpoints of Cisco Application Policy Infrastructure Controller (APIC) or
Cisco Cloud APIC could allow a remote attacker to perform a file upload attack on an affected system.

Affected Products
Cisco APIC and Cloud APIC.
Earlier than 3.2 Prior to 3.2(10f)
From 4.0 Prior to 4.2(7l)
From 5.0 Prior to 5.2(1g)
Note: Cisco Cloud APIC not supported.

QID Detection Logic (Authenticated):
The check matches Cisco APIC version retrieved via Unix Auth using "show version" command.

A successful exploit could allow the attacker to fill the upload partition of the affected device.

  • CVSS V3 rated as Critical - 9.1 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution

    Customers are advised to refer to cisco-sa-capic-mdvul-HBsJBuvW for more information.

    CVEs related to QID 317031

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-capic-mdvul-HBsJBuvW URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-capic-mdvul-HBsJBuvW