CVE-2021-1579 is a privilege escalation vulnerability affecting Cisco Application Policy Infrastructure Controller (APIC) and Cloud APIC. An authenticated, remote attacker with Administrator read-only credentials can exploit insufficient role-based access control (RBAC) to elevate their privileges to Administrator with write access. This vulnerability has a high CVSS score of 8.8, indicating a significant risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While the vulnerability is severe, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.2\(10f\)CPE matchmatch criteria | cpe:2.3:a:cisco:application_policy_infrastructure_controller:*:*:*:*:*:*:*:* | ||
>= 4.0, < 4.2\(7l\)CPE matchmatch criteria | cpe:2.3:a:cisco:application_policy_infrastructure_controller:*:*:*:*:*:*:*:* | ||
>= 5.0, < 5.2\(2f\)CPE matchmatch criteria | cpe:2.3:a:cisco:application_policy_infrastructure_controller:*:*:*:*:*:*:*:* | ||
< 3.2\(10f\)CPE matchmatch criteria | cpe:2.3:a:cisco:cloud_application_policy_infrastructure_controller:*:*:*:*:*:*:*:* | ||
>= 4.0, < 4.2\(7l\)CPE matchmatch criteria | cpe:2.3:a:cisco:cloud_application_policy_infrastructure_controller:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.