QID 317031
Date Published: 2021-09-09
QID 317031: Cisco Application Policy Infrastructure Controller (APIC) File Upload Vulnerabilities (cisco-sa-capic-mdvul-HBsJBuvW)
Multiple vulnerabilities in the web UI and API endpoints of Cisco Application Policy Infrastructure Controller (APIC) or
Cisco Cloud APIC could allow a remote attacker to perform a file upload attack on an affected system.
Affected Products
Cisco APIC and Cloud APIC.
Earlier than 3.2 Prior to 3.2(10f)
From 4.0 Prior to 4.2(7l)
From 5.0 Prior to 5.2(1g)
Note: Cisco Cloud APIC not supported.
QID Detection Logic (Authenticated):
The check matches Cisco APIC version retrieved via Unix Auth using "show version" command.
A successful exploit could allow the attacker to fill the upload partition of the affected device.
Solution
Customers are advised to refer to cisco-sa-capic-mdvul-HBsJBuvW for more information.
Vendor References
- cisco-sa-capic-mdvul-HBsJBuvW -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-capic-mdvul-HBsJBuvW
CVEs related to QID 317031
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-capic-mdvul-HBsJBuvW |
|