ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Critical Flaw Discovered in Cisco APIC for Switches — Patch Released

criticalVulnerabilityimportance 60CVE-2021-1577

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-1577
A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Controller (Cl

A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Controller (Cloud APIC) could allow an unauthenticated, remote attacker to read or write arbitrary files on an affected system. This vulnerability is due to improper access control. An attacker could exploit this vulnerability by using a specific API endpoint to upload a file to an affected device. A successful exploit could allow the attacker to read or write arbitrary files on an affected device.

NVD description · AI analysis pending
9.11%
  • cisco application policy infrastructure controller
  • cisco cloud application policy infrastructure controller
Full article264 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananAug 26, 2021

Cisco Systems on Wednesday issued patches to address a critical security vulnerability affecting the Application Policy Infrastructure Controller (APIC) interface used in its Nexus 9000 Series Switches that could be potentially abused to read or write arbitrary files on a vulnerable system.

Tracked as CVE-2021-1577 (CVSS score: 9.1), the issue — which is due to improper access control — could enable an unauthenticated, remote attacker to upload a file to the appliances. " A successful exploit could allow the attacker to read or write arbitrary files on an affected device," the company said in an advisory.

The APIC appliance is a centralized, clustered controller that programmatically automates network provisioning and control based on the application requirements and policies across physical and virtual environments.

Cisco said it discovered the vulnerability during internal security testing by the Cisco Advanced Security Initiatives Group (ASIG).

Additionally, the network equipment major said it concluded its investigation into a new BadAlloc flaw in BlackBerry's QNX real-time operating system, reported on August 17 by the Canadian company. "Cisco has completed its investigation into its product line to determine which products may be affected by this vulnerability. No products are known to be affected," it noted.

Cisco products that run QNX are listed below -

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2021/08/critical-flaw-discovered-in-cisco-apic.html