← Vulnerability feed

Vulnerability record · CVE-2020-3139 · published 26 January 2020

CVE-2020-3139: Cisco application policy infrastructure controller improper input validation vulnerability

Cisco · Application Policy Infrastructure Controller

A vulnerability in the out of band (OOB) management interface IP table rule programming for Cisco Application Policy Infrastructure Controller (APIC) could allow an unauthenticated, remote attacker to bypass configured deny entries for specific IP ports. These IP ports would be permitted to the OOB management interface when, in fact, the packets should be dropped. The vulnerability is due to the configuration of specific IP table entries for which there is a programming logic error that results in the IP port being permitted. An attacker could exploit this vulnerability by sending traffic to the OOB management interface on the targeted device. A successful exploit could allow the attacker to bypass configured IP table rules to drop specific IP port traffic. The attacker has no control over the configuration of the device itself. This vulnerability affects Cisco APIC releases prior to the first fixed software Release 4.2(3j).

5.3 CVSS 3.1 Medium EPSS 1.0% · top 37.4% CWE-20 · Improper input validation
5.3CVSS 3.1 base score, v2 5.0
1.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the out of band (OOB) management interface IP table rule programming for Cisco Application Policy Infrastructure Controller (APIC) could allow an unauthenticated, remote attacker to bypass configured deny entries for specific IP ports. These IP ports would be permitted to the OOB management interface when, in fact, the packets should be dropped. The vulnerability is due to the configuration of specific IP table entries for which there is a programming logic error that results in the IP port being permitted. An attacker could exploit this vulnerability by sending traffic to the OOB management interface on the targeted device. A successful exploit could allow the attacker to bypass configured IP table rules to drop specific IP port traffic. The attacker has no control over the configuration of the device itself. This vulnerability affects Cisco APIC releases prior to the first fixed software Release 4.2(3j).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-3139 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-1388Cisco aci multi-site orchestrator improper privilege management vulnerabilityA vulnerability in an API endpoint of Cisco ACI Multi-Site Orchestrator (MSO) installed on the Application Services Engine could allow an unauthentic…EPSS 15%9.8CVE-2021-1393Cisco application services engine missing authentication for critical function vulnerabilityMultiple vulnerabilities in Cisco Application Services Engine could allow an unauthenticated, remote attacker to gain privileged access to host-level…EPSS 2.3%9.1CVE-2021-1581Cisco application policy infrastructure controller improper access control vulnerabilityMultiple vulnerabilities in the web UI and API endpoints of Cisco Application Policy Infrastructure Controller (APIC) or Cisco Cloud APIC could allow…EPSS 1.1%9.1CVE-2021-1577Cisco application policy infrastructure controller improper access control vulnerabilityA vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Con…EPSS 1.3%8.8CVE-2023-20011Cisco application policy infrastructure controller cross-site request forgery vulnerabilityA vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Network Controller…EPSS 0.36%8.8CVE-2021-1578Cisco application policy infrastructure controller vulnerabilityA vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Con…EPSS 2.0%8.8CVE-2021-1579Cisco application policy infrastructure controller execution with unnecessary privileges vulnerabilityA vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Con…EPSS 2.1%7.8CVE-2019-1682Cisco application policy infrastructure controller permissions and access controls vulnerabilityA vulnerability in the FUSE filesystem functionality for Cisco Application Policy Infrastructure Controller (APIC) software could allow an authentica…EPSS 0.35%

Source: NIST National Vulnerability Database (record CVE-2020-3139), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.