CVE-2016-1420 describes a critical vulnerability in Cisco Application Policy Infrastructure Controller (APIC) devices running software versions prior to 1.3(2f). The flaw resides within the installation component, which improperly handles binary files. This misconfiguration allows a local attacker to achieve root access through unspecified vectors. The vulnerability carries a CVSSv3 score of 7.8 (High), indicating a significant risk. It requires local access and low privileges (AV:L/PR:L), but successful exploitation grants full confidentiality, integrity, and availability impact (C:H/I:H/A:H) to the attacker. Currently, there is no evidence of active exploitation, nor is public exploit code available in Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community discussion and media coverage, suggesting a low profile despite its high severity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:cisco:application_infrastructure_controller:-:*:*:*:*:*:*:* | ||
1.0\(1e\)CPE matchmatch criteria | cpe:2.3:o:cisco:application_policy_infrastructure_controller_firmware:1.0\(1e\):*:*:*:*:*:*:* | ||
1.0\(1h\)CPE matchmatch criteria | cpe:2.3:o:cisco:application_policy_infrastructure_controller_firmware:1.0\(1h\):*:*:*:*:*:*:* | ||
1.0\(1k\)CPE matchmatch criteria | cpe:2.3:o:cisco:application_policy_infrastructure_controller_firmware:1.0\(1k\):*:*:*:*:*:*:* | ||
1.0\(1n\)CPE matchmatch criteria | cpe:2.3:o:cisco:application_policy_infrastructure_controller_firmware:1.0\(1n\):*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.