VYPR

Application Policy Infrastructure Controller

by Cisco Systems, Inc.

CVEs (36)

  • CVE-2025-20119MedFeb 26, 2025
    risk 0.39cvss 6.0epss 0.00

    A vulnerability in the system file permission handling of Cisco APIC could allow an authenticated, local attacker to overwrite critical system files, which could cause a DoS condition. To exploit this vulnerability, the attacker must have valid administrative credentials. …

  • CVE-2026-20107MedFeb 25, 2026
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in the Object Model CLI component of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, local attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. To exploit this…

  • CVE-2020-3335MedJun 3, 2020
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in the key store of Cisco Application Services Engine Software could allow an authenticated, local attacker to read sensitive information of other users on an affected device. The vulnerability is due to insufficient authorization limitations. An attacker could…

  • CVE-2023-20230MedAug 23, 2023
    risk 0.35cvss 5.4epss 0.00

    A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to read, modify, or delete non-tenant policies (for example, access policies) created by users associated…

  • CVE-2021-1582MedAug 25, 2021
    risk 0.35cvss 5.4epss 0.01

    A vulnerability in the web UI of Cisco Application Policy Infrastructure Controller (APIC) or Cisco Cloud APIC could allow an authenticated, remote attacker to perform a stored cross-site scripting attack on an affected system. This vulnerability is due to improper input…

  • CVE-2020-3333MedJun 3, 2020
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in the API of Cisco Application Services Engine Software could allow an unauthenticated, remote attacker to update event policies on an affected device. The vulnerability is due to insufficient authentication of users who modify policies on an affected device. An…

  • CVE-2020-3139MedJan 26, 2020
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in the out of band (OOB) management interface IP table rule programming for Cisco Application Policy Infrastructure Controller (APIC) could allow an unauthenticated, remote attacker to bypass configured deny entries for specific IP ports. These IP ports would be…

  • CVE-2019-1838MedMay 3, 2019
    risk 0.35cvss 5.4epss 0.01

    A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected…

  • CVE-2019-1692MedMay 3, 2019
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) Software could allow an unauthenticated, remote attacker to access sensitive system usage information. The vulnerability is due to a lack of proper data protection…

  • CVE-2025-20117MedFeb 26, 2025
    risk 0.33cvss 5.1epss 0.00

    A vulnerability in the CLI of Cisco APIC could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. …

  • CVE-2025-20116MedFeb 26, 2025
    risk 0.31cvss 4.8epss 0.00

    A vulnerability in the web UI of Cisco APIC could allow an authenticated, remote attacker to perform a stored XSS attack on an affected system. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper input…

  • CVE-2019-1586MedMay 3, 2019
    risk 0.30cvss 4.6epss 0.00

    A vulnerability in Cisco Application Policy Infrastructure Controller (APIC) Software could allow an unauthenticated, local attacker with physical access to obtain sensitive information from an affected device. The vulnerability is due to insecure removal of cleartext encryption…

  • CVE-2025-20118MedFeb 26, 2025
    risk 0.29cvss 4.4epss 0.00

    A vulnerability in the implementation of the internal system processes of Cisco APIC could allow an authenticated, local attacker to access sensitive information on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. …

  • CVE-2024-20279MedAug 28, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to modify the behavior of default system policies, such as quality of service (QoS) policies, on an…

  • CVE-2015-6424Dec 18, 2015
    risk 0.00cvss epss 0.00

    The boot manager in Cisco Application Policy Infrastructure Controller (APIC) 1.1(0.920a) allows local users to bypass intended access restrictions and obtain single-user-mode root access via unspecified vectors, aka Bug ID CSCuu83985.

  • CVE-2015-6333Oct 16, 2015
    risk 0.00cvss epss 0.00

    Cisco Application Policy Infrastructure Controller (APIC) 1.1j allows local users to gain privileges via vectors involving addition of an SSH key, aka Bug ID CSCuw46076.

Page 2 of 2