Application Policy Infrastructure Controller Enterprise Module
Vendor:
First CVE: Jan 26, 2016 · Active for 10 years
8
Total CVEs
More Total CVEs than 85% of tracked products
2.7
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 50% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Application Policy Infrastructure Controller Enterprise Module over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 26, 2016
10 years ago
Most Recent CVE
Aug 15, 2018
2,901 days ago
CVE Severity & Scoring
Application Policy Infrastructure Controller Enterprise Module8 CVEs
38%
63%
All CVEs352,708 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local1 (12.5%)
Network6 (75.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (12.5%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (62.5%)
Unknown0 (0.0%)
Required3 (37.5%)
Privileges Required
Low3 (37.5%)
High0 (0.0%)
None5 (62.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-0427HIGH A vulnerability in the CronJob scheduler API of Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to perform a command injection attack. | Aug 15, 2018 | 8.8 | 30 | NO | NO |
CVE-2016-1365HIGH The Grapevine update process in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.0 allows remote authenticated users to execute arbitrary commands a | Aug 18, 2016 | 8.8 | 29 | NO | NO |
CVE-2018-0368HIGH A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an authenticated, local attacker to access sensitive information on an affected system. The vulnerabi | Jul 16, 2018 | 7.8 | 24 | NO | NO |
CVE-2016-1386HIGH The API in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.0(1) allows remote attackers to spoof administrative notifications via crafted attribute | Apr 28, 2016 | 7.5 | 24 | NO | NO |
CVE-2017-12262HIGH A vulnerability within the firewall configuration of the Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) could allow an unauthenticated, adjacent att | Nov 2, 2017 | 8.8 | 22 | NO | NO |
CVE-2016-1318MEDIUM Cross-site scripting (XSS) vulnerability in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.1 allows remote attackers to inject arbitrary web scrip | Feb 9, 2016 | 6.1 | 18 | NO | NO |
CVE-2016-1305MEDIUM Cross-site scripting (XSS) vulnerability in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.1 allows remote attackers to inject arbitrary web scrip | Feb 7, 2016 | 6.1 | 17 | NO | NO |
CVE-2015-6337MEDIUM Cross-site scripting (XSS) vulnerability in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.0.10 allows remote attackers to inject arbitrary web sc | Jan 26, 2016 | 6.1 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Application Policy Infrastructure Controller Enterprise Module
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| dnac1.1 | 1 | 8.8 | 6.1% | 0 | 0 |
| 1.1_base | 3 | 6.7 | 0.8% | 0 | 0 |
| 1.0_ga | 1 | 6.1 | 1.0% | 0 | 0 |
| 1.0.10 | 2 | 7.5 | 1.8% | 0 | 0 |
| 1.0.\(1\) | 1 | 7.5 | 1.1% | 0 | 0 |