📦 Application Policy Infrastructure Controller

by Cisco

🔍 What is Application Policy Infrastructure Controller?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-1577

CRITICAL CVSS 9.1 Aug 25, 2021

This vulnerability allows unauthenticated remote attackers to read or write arbitrary files on Cisco APIC and Cloud APIC systems due to improper access control in a specific API endpoint. Attackers ca...

CVE-2021-1388

CRITICAL CVSS 10.0 Feb 24, 2021

This vulnerability allows unauthenticated remote attackers to bypass authentication on Cisco ACI Multi-Site Orchestrator (MSO) by exploiting improper token validation in a specific API endpoint. Succe...

CVE-2021-1396

CRITICAL CVSS 9.8 Feb 24, 2021

Multiple vulnerabilities in Cisco Application Services Engine allow unauthenticated remote attackers to gain privileged access to host-level operations, access device-specific information, create diag...

CVE-2023-20011

HIGH CVSS 8.8 Feb 23, 2023

This CSRF vulnerability in Cisco APIC and Cloud Network Controller web interfaces allows unauthenticated attackers to trick authenticated users into executing malicious actions via crafted links. If e...

CVE-2021-1579

HIGH CVSS 8.1 Aug 25, 2021

This vulnerability allows authenticated remote attackers with Administrator read-only credentials to elevate privileges to Administrator with write privileges on Cisco APIC and Cloud APIC systems. Att...

CVE-2025-20116

MEDIUM CVSS 4.8 Feb 26, 2025

This stored XSS vulnerability in Cisco APIC's web UI allows authenticated administrators to inject malicious scripts that execute when other users view affected pages. Only systems running vulnerable ...

CVE-2025-20118

MEDIUM CVSS 4.4 Feb 26, 2025

This vulnerability in Cisco APIC allows authenticated local administrators to access sensitive information through insufficiently masked CLI command outputs. Attackers with valid administrative creden...