← Vulnerability feed

Vulnerability record · CVE-2023-20230 · published 23 August 2023

CVE-2023-20230: Cisco application policy infrastructure controller improper access control vulnerability

Cisco · Application Policy Infrastructure Controller

A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to read, modify, or delete non-tenant policies (for example, access policies) created by users associated with a different security domain on an affected system. This vulnerability is due to improper access control when restricted security domains are used to implement multi-tenancy for policies outside the tenant boundaries. An attacker with a valid user account associated with a restricted security domain could exploit this vulnerability. A successful exploit could allow the attacker to read, modify, or delete policies created by users associated with a different security domain. Exploitation is not possible for policies under tenants that an attacker has no authorization to access.

5.4 CVSS 3.1 Medium EPSS 0.44% · top 64.3% CWE-284 · Improper access controlCWE-732 · Incorrect permission assignment
5.4CVSS 3.1 base score
0.44%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to read, modify, or delete non-tenant policies (for example, access policies) created by users associated with a different security domain on an affected system. This vulnerability is due to improper access control when restricted security domains are used to implement multi-tenancy for policies outside the tenant boundaries. An attacker with a valid user account associated with a restricted security domain could exploit this vulnerability. A successful exploit could allow the attacker to read, modify, or delete policies created by users associated with a different security domain. Exploitation is not possible for policies under tenants that an attacker has no authorization to access.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-20230 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-1388Cisco aci multi-site orchestrator improper privilege management vulnerabilityA vulnerability in an API endpoint of Cisco ACI Multi-Site Orchestrator (MSO) installed on the Application Services Engine could allow an unauthentic…EPSS 15%9.8CVE-2021-1393Cisco application services engine missing authentication for critical function vulnerabilityMultiple vulnerabilities in Cisco Application Services Engine could allow an unauthenticated, remote attacker to gain privileged access to host-level…EPSS 2.3%9.1CVE-2021-1581Cisco application policy infrastructure controller improper access control vulnerabilityMultiple vulnerabilities in the web UI and API endpoints of Cisco Application Policy Infrastructure Controller (APIC) or Cisco Cloud APIC could allow…EPSS 1.1%9.1CVE-2021-1577Cisco application policy infrastructure controller improper access control vulnerabilityA vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Con…EPSS 1.3%8.8CVE-2023-20011Cisco application policy infrastructure controller cross-site request forgery vulnerabilityA vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Network Controller…EPSS 0.36%8.8CVE-2021-1578Cisco application policy infrastructure controller vulnerabilityA vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Con…EPSS 2.0%8.8CVE-2021-1579Cisco application policy infrastructure controller execution with unnecessary privileges vulnerabilityA vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Con…EPSS 2.1%7.8CVE-2019-1682Cisco application policy infrastructure controller permissions and access controls vulnerabilityA vulnerability in the FUSE filesystem functionality for Cisco Application Policy Infrastructure Controller (APIC) software could allow an authentica…EPSS 0.35%

Source: NIST National Vulnerability Database (record CVE-2023-20230), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.