← Vulnerability feed

Vulnerability record · CVE-2021-1578 · published 25 August 2021

CVE-2021-1578: Cisco application policy infrastructure controller vulnerability

Cisco · Application Policy Infrastructure Controller

A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Controller (Cloud APIC) could allow an authenticated, remote attacker to elevate privileges to Administrator on an affected device. This vulnerability is due to an improper policy default setting. An attacker could exploit this vulnerability by using a non-privileged credential for Cisco ACI Multi-Site Orchestrator (MSO) to send a specific API request to a managed Cisco APIC or Cloud APIC device. A successful exploit could allow the attacker to obtain Administrator credentials on the affected device.

8.8 CVSS 3.1 High EPSS 2.0% · top 20.4% CWE-636 · CWE-636CWE-755 · CWE-755
8.8CVSS 3.1 base score, v2 9.0
2.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Controller (Cloud APIC) could allow an authenticated, remote attacker to elevate privileges to Administrator on an affected device. This vulnerability is due to an improper policy default setting. An attacker could exploit this vulnerability by using a non-privileged credential for Cisco ACI Multi-Site Orchestrator (MSO) to send a specific API request to a managed Cisco APIC or Cloud APIC device. A successful exploit could allow the attacker to obtain Administrator credentials on the affected device.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-1578 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-1388Cisco aci multi-site orchestrator improper privilege management vulnerabilityA vulnerability in an API endpoint of Cisco ACI Multi-Site Orchestrator (MSO) installed on the Application Services Engine could allow an unauthentic…EPSS 15%9.8CVE-2021-1393Cisco application services engine missing authentication for critical function vulnerabilityMultiple vulnerabilities in Cisco Application Services Engine could allow an unauthenticated, remote attacker to gain privileged access to host-level…EPSS 2.3%9.1CVE-2021-1581Cisco application policy infrastructure controller improper access control vulnerabilityMultiple vulnerabilities in the web UI and API endpoints of Cisco Application Policy Infrastructure Controller (APIC) or Cisco Cloud APIC could allow…EPSS 1.1%9.1CVE-2021-1577Cisco application policy infrastructure controller improper access control vulnerabilityA vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Con…EPSS 1.3%8.8CVE-2023-20011Cisco application policy infrastructure controller cross-site request forgery vulnerabilityA vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Network Controller…EPSS 0.36%8.8CVE-2021-1579Cisco application policy infrastructure controller execution with unnecessary privileges vulnerabilityA vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Con…EPSS 2.1%7.8CVE-2019-1682Cisco application policy infrastructure controller permissions and access controls vulnerabilityA vulnerability in the FUSE filesystem functionality for Cisco Application Policy Infrastructure Controller (APIC) software could allow an authentica…EPSS 0.35%7.8CVE-2017-6768Cisco application policy infrastructure controller untrusted search path vulnerabilityA vulnerability in the build procedure for certain executable system files installed at boot time on Cisco Application Policy Infrastructure Controll…EPSS 0.42%

Source: NIST National Vulnerability Database (record CVE-2021-1578), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.