Application Policy Infrastructure Controller
Vendor:
First CVE: Oct 16, 2015 · Active for 10 years
34
Total CVEs
More Total CVEs than 96% of tracked products
3.8
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Application Policy Infrastructure Controller over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 16, 2015
10 years ago
Most Recent CVE
Feb 26, 2025
513 days ago
CVE Severity & Scoring
Application Policy Infrastructure Controller34 CVEs
56%
32%
12%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local8 (23.5%)
Network20 (58.8%)
Unknown2 (5.9%)
Physical1 (2.9%)
Adjacent Network3 (8.8%)
Attack Complexity
Low30 (88.2%)
High2 (5.9%)
Unknown2 (5.9%)
User Interaction
None27 (79.4%)
Unknown2 (5.9%)
Required5 (14.7%)
Privileges Required
Low11 (32.4%)
High8 (23.5%)
None13 (38.2%)
Unknown2 (5.9%)
Top CVEs
Signals from CVEs in this product scope (34 CVEs).
34 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-1388CRITICAL A vulnerability in an API endpoint of Cisco ACI Multi-Site Orchestrator (MSO) installed on the Application Services Engine could allow an unauthenticated, remote attacker to bypass | Feb 24, 2021 | 10.0 | 38 | NO | NO |
CVE-2021-1393CRITICAL Multiple vulnerabilities in Cisco Application Services Engine could allow an unauthenticated, remote attacker to gain privileged access to host-level operations or to learn device- | Feb 24, 2021 | 9.8 | 31 | NO | NO |
CVE-2021-1581CRITICAL Multiple vulnerabilities in the web UI and API endpoints of Cisco Application Policy Infrastructure Controller (APIC) or Cisco Cloud APIC could allow a remote attacker to perform a | Aug 25, 2021 | 9.1 | 29 | NO | NO |
CVE-2021-1578HIGH A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Controller (Cloud APIC) could allo | Aug 25, 2021 | 8.8 | 29 | NO | NO |
CVE-2021-1577CRITICAL A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Controller (Cloud APIC) could allo | Aug 25, 2021 | 9.1 | 29 | NO | NO |
CVE-2021-1579HIGH A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Controller (Cloud APIC) could allo | Aug 25, 2021 | 8.8 | 28 | NO | NO |
CVE-2021-1580HIGH Multiple vulnerabilities in the web UI and API endpoints of Cisco Application Policy Infrastructure Controller (APIC) or Cisco Cloud APIC could allow a remote attacker to perform a | Aug 25, 2021 | 7.2 | 25 | NO | NO |
CVE-2019-1889HIGH A vulnerability in the REST API for software device management in Cisco Application Policy Infrastructure Controller (APIC) Software could allow an authenticated, remote attacker t | Jul 4, 2019 | 7.2 | 25 | NO | NO |
CVE-2019-1682HIGH A vulnerability in the FUSE filesystem functionality for Cisco Application Policy Infrastructure Controller (APIC) software could allow an authenticated, local attacker to escalate | May 3, 2019 | 7.8 | 24 | NO | NO |
CVE-2019-1890MEDIUM A vulnerability in the fabric infrastructure VLAN connection establishment of the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow | Jul 4, 2019 | 6.5 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (34 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (34 CVEs).
Media Mentions
Signals from CVEs in this product scope (34 CVEs).
Top CNAs Publishing CVEs For Application Policy Infrastructure Controller
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8.3\(1\)s6 | 1 | 5.3 | 1.2% | 0 | 0 |
| 7.3\(0\)zn\(0.113\) | 1 | 6.5 | 0.6% | 0 | 0 |
| 6.1\(1f\) | 4 | 5.4 | 0.2% | 0 | 0 |
| 6.0\(8d\) | 4 | 5.4 | 0.2% | 0 | 0 |
| 6.0\(7e\) | 4 | 5.4 | 0.2% | 0 | 0 |
| 6.0\(6c\) | 4 | 5.4 | 0.2% | 0 | 0 |
| 6.0\(5j\) | 6 | 5.5 | 0.3% | 0 | 0 |
| 6.0\(5h\) | 6 | 5.5 | 0.3% | 0 | 0 |
| 6.0\(4c\) | 6 | 5.5 | 0.3% | 0 | 0 |
| 6.0\(3g\) | 6 | 5.5 | 0.3% | 0 | 0 |
| 6.0\(3e\) | 6 | 5.5 | 0.3% | 0 | 0 |
| 6.0\(3d\) | 6 | 5.5 | 0.3% | 0 | 0 |
| 6.0\(2j\) | 6 | 5.5 | 0.3% | 0 | 0 |
| 6.0\(2h\) | 6 | 5.5 | 0.3% | 0 | 0 |
| 6.0\(1j\) | 6 | 5.5 | 0.3% | 0 | 0 |
| 6.0\(1g\) | 6 | 5.5 | 0.3% | 0 | 0 |
| 5.3\(2e\) | 4 | 5.4 | 0.2% | 0 | 0 |
| 5.3\(2d\) | 4 | 5.4 | 0.2% | 0 | 0 |
| 5.3\(2c\) | 5 | 5.8 | 0.3% | 0 | 0 |
| 5.3\(2b\) | 6 | 5.5 | 0.3% | 0 | 0 |