CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2021-1393

CVSS 9.8v3.1pub. 2021-02-24upd. 2024-11-21

Multiple vulnerabilities in Cisco Application Services Engine could allow an unauthenticated, remote attacker to gain privileged access to host-level operations or to learn device-specific information, create diagnostic files, and make limited configuration changes. For more information about these vulnerabilities, see the Details section of this advisory.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Cisco Application Policy Infrastructure Controller

    APP
    Cisco
    1.1.3
  • Cisco Application Services Engine

    APP
    Cisco
    1.1 – 1.1\(3e\) (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2021-1577CRITICAL9.1PL ✓same product

Cisco APIC: nieautoryzowany odczyt i zapis plików przez API

CVE-2021-1388CRITICAL10.0PL ✓same product

Cisco ACI MSO — pominięcie uwierzytelniania w API (Auth Bypass)

CVE-2021-1396CRITICAL9.8PL ✓same product

Cisco Application Services Engine — nieautoryzowany dostęp uprzywilejowany

CVE-2023-20011HIGH8.8same product

A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (A...

CVE-2021-1578HIGH8.8same product

A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Clou...