QID 317301

Date Published: 2023-03-15

QID 317301: Cisco Application Policy Infrastructure Controller (APIC) Cross-Site Request Forgery (CSRF) Vulnerability (cisco-sa-capic-csrfv-DMx6KSwV)

A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Network Controller, formerly Cisco Cloud APIC, could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system.

Affected Products:
Cisco APIC Release 4.2(6) and later prior to 5.2(7g)
Cisco APIC Release 6.0 prior to 6.0(2e)

QID Detection Logic(Authenticated):
The check matches Cisco APIC version retrieved via Unix Auth using "show version" command.

A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution

    Customers are advised to refer to cisco-sa-capic-csrfv-DMx6KSwV for more information.

    CVEs related to QID 317301

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-capic-csrfv-DMx6KSwV URL Logo sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-capic-csrfv-DMx6KSwV