CVE-2021-1388
CRITICALCisco ACI Multi-Site Orchestrator 3.0-3.0(3m) - Unauthenticated Authentication Bypass via API Endpoint
Title source: llmDescription
A vulnerability in an API endpoint of Cisco ACI Multi-Site Orchestrator (MSO) installed on the Application Services Engine could allow an unauthenticated, remote attacker to bypass authentication on an affected device. The vulnerability is due to improper token validation on a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted request to the affected API. A successful exploit could allow the attacker to receive a token with administrator-level privileges that could be used to authenticate to the API on affected MSO and managed Cisco Application Policy Infrastructure Controller (APIC) devices.
References (1)
Core 1
Core References
Vendor Advisory vendor-advisory
x_refsource_cisco
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-mso-authbyp-bb5GmBQv
Scores
CVSS v3
10.0
EPSS
0.0196
EPSS Percentile
83.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-269
Status
published
Products (2)
cisco/aci_multi-site_orchestrator
3.0 - 3.0\(3m\)
cisco/application_policy_infrastructure_controller
3.0\(3i\)
Published
Feb 24, 2021
Tracked Since
Feb 18, 2026