Application Policy Infrastructure Controller

Vendor:

First CVE: Oct 16, 2015 · Active for 10 years

34
Total CVEs
More Total CVEs than 96% of tracked products
3.8
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Application Policy Infrastructure Controller over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 16, 2015
10 years ago
Most Recent CVE
Feb 26, 2025
513 days ago

CVE Severity & Scoring

Application Policy Infrastructure Controller34 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local8 (23.5%)
Network20 (58.8%)
Unknown2 (5.9%)
Physical1 (2.9%)
Adjacent Network3 (8.8%)
Attack Complexity
Low30 (88.2%)
High2 (5.9%)
Unknown2 (5.9%)
User Interaction
None27 (79.4%)
Unknown2 (5.9%)
Required5 (14.7%)
Privileges Required
Low11 (32.4%)
High8 (23.5%)
None13 (38.2%)
Unknown2 (5.9%)

Top CVEs

Signals from CVEs in this product scope (34 CVEs).

34 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A vulnerability in an API endpoint of Cisco ACI Multi-Site Orchestrator (MSO) installed on the Application Services Engine could allow an unauthenticated, remote attacker to bypass
Feb 24, 202110.038NONO
Multiple vulnerabilities in Cisco Application Services Engine could allow an unauthenticated, remote attacker to gain privileged access to host-level operations or to learn device-
Feb 24, 20219.831NONO
Multiple vulnerabilities in the web UI and API endpoints of Cisco Application Policy Infrastructure Controller (APIC) or Cisco Cloud APIC could allow a remote attacker to perform a
Aug 25, 20219.129NONO
A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Controller (Cloud APIC) could allo
Aug 25, 20218.829NONO
A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Controller (Cloud APIC) could allo
Aug 25, 20219.129NONO
A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Controller (Cloud APIC) could allo
Aug 25, 20218.828NONO
Multiple vulnerabilities in the web UI and API endpoints of Cisco Application Policy Infrastructure Controller (APIC) or Cisco Cloud APIC could allow a remote attacker to perform a
Aug 25, 20217.225NONO
A vulnerability in the REST API for software device management in Cisco Application Policy Infrastructure Controller (APIC) Software could allow an authenticated, remote attacker t
Jul 4, 20197.225NONO
A vulnerability in the FUSE filesystem functionality for Cisco Application Policy Infrastructure Controller (APIC) software could allow an authenticated, local attacker to escalate
May 3, 20197.824NONO
A vulnerability in the fabric infrastructure VLAN connection establishment of the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow
Jul 4, 20196.523NONO

Exploit Exposure

Signals from CVEs in this product scope (34 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (34 CVEs).

Media Mentions

Signals from CVEs in this product scope (34 CVEs).

Top CNAs Publishing CVEs For Application Policy Infrastructure Controller

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
8.3\(1\)s615.31.2%00
7.3\(0\)zn\(0.113\)16.50.6%00
6.1\(1f\)45.40.2%00
6.0\(8d\)45.40.2%00
6.0\(7e\)45.40.2%00
6.0\(6c\)45.40.2%00
6.0\(5j\)65.50.3%00
6.0\(5h\)65.50.3%00
6.0\(4c\)65.50.3%00
6.0\(3g\)65.50.3%00
6.0\(3e\)65.50.3%00
6.0\(3d\)65.50.3%00
6.0\(2j\)65.50.3%00
6.0\(2h\)65.50.3%00
6.0\(1j\)65.50.3%00
6.0\(1g\)65.50.3%00
5.3\(2e\)45.40.2%00
5.3\(2d\)45.40.2%00
5.3\(2c\)55.80.3%00
5.3\(2b\)65.50.3%00