
CVE-2019-1690 – Cisco Application Policy Infrastructure Controller IPv6 Link-Local Address Vulnerability
https://notcve.org/view.php?id=CVE-2019-1690
11 Mar 2019 — A vulnerability in the management interface of Cisco Application Policy Infrastructure Controller (APIC) software could allow an unauthenticated, adjacent attacker to gain unauthorized access on an affected device. The vulnerability is due to a lack of proper access control mechanisms for IPv6 link-local connectivity imposed on the management interface of an affected device. An attacker on the same physical network could exploit this vulnerability by attempting to connect to the IPv6 link-local address on t... • http://www.securityfocus.com/bid/107317 • CWE-284: Improper Access Control •

CVE-2017-6767
https://notcve.org/view.php?id=CVE-2017-6767
17 Aug 2017 — A vulnerability in Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to gain higher privileges than the account is assigned. The attacker will be granted the privileges of the last user to log in, regardless of whether those privileges are higher or lower than what should have been granted. The attacker cannot gain root-level privileges. The vulnerability is due to a limitation with how Role-Based Access Control (RBAC) grants privileges to remotely authe... • http://www.securityfocus.com/bid/100400 • CWE-269: Improper Privilege Management •

CVE-2017-6768
https://notcve.org/view.php?id=CVE-2017-6768
17 Aug 2017 — A vulnerability in the build procedure for certain executable system files installed at boot time on Cisco Application Policy Infrastructure Controller (APIC) devices could allow an authenticated, local attacker to gain root-level privileges. The vulnerability is due to a custom executable system file that was built to use relative search paths for libraries without properly validating the library to be loaded. An attacker could exploit this vulnerability by authenticating to the device and loading a malici... • http://www.securityfocus.com/bid/100363 • CWE-426: Untrusted Search Path •

CVE-2015-6424
https://notcve.org/view.php?id=CVE-2015-6424
18 Dec 2015 — The boot manager in Cisco Application Policy Infrastructure Controller (APIC) 1.1(0.920a) allows local users to bypass intended access restrictions and obtain single-user-mode root access via unspecified vectors, aka Bug ID CSCuu83985. El boot manager en Cisco Application Policy Infrastructure Controller (APIC) 1.1(0.920a) permite a usuarios locales eludir las restricciones destinadas al acceso y obtener acceso root modo-solo-usuario a través de vectores no especificados, también conocido como Bug ID CSCuu8... • http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151216-apic • CWE-255: Credentials Management Errors •

CVE-2015-6333
https://notcve.org/view.php?id=CVE-2015-6333
16 Oct 2015 — Cisco Application Policy Infrastructure Controller (APIC) 1.1j allows local users to gain privileges via vectors involving addition of an SSH key, aka Bug ID CSCuw46076. Cisco Application Policy Infrastructure Controller (APIC) 1.1j permite a usuarios locales ganar privilegios a través de vectores que involucran la adición de una llave SSH, también conocido como Bug ID CSCuw46076. • http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151012-apic • CWE-264: Permissions, Privileges, and Access Controls •