Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-1388

Опубликовано: 24 фев. 2021
Источник: nvd
CVSS3: 10
CVSS2: 9.3
EPSS Низкий

Описание

A vulnerability in an API endpoint of Cisco ACI Multi-Site Orchestrator (MSO) installed on the Application Services Engine could allow an unauthenticated, remote attacker to bypass authentication on an affected device. The vulnerability is due to improper token validation on a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted request to the affected API. A successful exploit could allow the attacker to receive a token with administrator-level privileges that could be used to authenticate to the API on affected MSO and managed Cisco Application Policy Infrastructure Controller (APIC) devices.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cisco:aci_multi-site_orchestrator:*:*:*:*:*:*:*:*
Версия от 3.0 (включая) до 3.0\(3m\) (исключая)
cpe:2.3:a:cisco:application_policy_infrastructure_controller:3.0\(3i\):*:*:*:*:*:*:*

EPSS

Процентиль: 83%
0.01958
Низкий

10 Critical

CVSS3

9.3 Critical

CVSS2

Дефекты

CWE-269
NVD-CWE-Other

Связанные уязвимости

CVSS3: 10
github
больше 3 лет назад

A vulnerability in an API endpoint of Cisco ACI Multi-Site Orchestrator (MSO) installed on the Application Services Engine could allow an unauthenticated, remote attacker to bypass authentication on an affected device. The vulnerability is due to improper token validation on a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted request to the affected API. A successful exploit could allow the attacker to receive a token with administrator-level privileges that could be used to authenticate to the API on affected MSO and managed Cisco Application Policy Infrastructure Controller (APIC) devices.

CVSS3: 10
fstec
почти 5 лет назад

Уязвимость компонента API диспетчера межсайтовых политик Cisco ACI Multi-Site Orchestrator (MSO), позволяющая нарушителю получить токен с правами администратора

EPSS

Процентиль: 83%
0.01958
Низкий

10 Critical

CVSS3

9.3 Critical

CVSS2

Дефекты

CWE-269
NVD-CWE-Other