peter bassill · operator
$ cve CVE-2021-1388 JSON

CVE-2021-1388

10.0
CRITICAL · CVSS 3.1 · EPSS 14.8% (pctl 97)

Patch early

EPSS 14.8% — above the 10% action threshold.

Description

A vulnerability in an API endpoint of Cisco ACI Multi-Site Orchestrator (MSO) installed on the Application Services Engine could allow an unauthenticated, remote attacker to bypass authentication on an affected device. The vulnerability is due to improper token validation on a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted request to the affected API. A successful exploit could allow the attacker to receive a token with administrator-level privileges that could be used to authenticate to the API on affected MSO and managed Cisco Application Policy Infrastructure Controller (APIC) devices.

Scoring

CVSS10.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS14.85% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-269
On CISA KEVno
Public exploitnone known
Published2021-02-24
Last modified2026-06-17

Affected (2)

VendorProduct
ciscoaci multi-site orchestrator
ciscoapplication policy infrastructure controller

References

→ the Explorer  ·  watch your stack  ·  NVD