CVE-2021-1577

CRITICAL

Cisco APIC/Cloud APIC Unauthenticated Arbitrary File Read/Write via API

Title source: llm
STIX 2.1

Description

A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Controller (Cloud APIC) could allow an unauthenticated, remote attacker to read or write arbitrary files on an affected system. This vulnerability is due to improper access control. An attacker could exploit this vulnerability by using a specific API endpoint to upload a file to an affected device. A successful exploit could allow the attacker to read or write arbitrary files on an affected device.

References (1)

Core 1
Core References

Scores

CVSS v3 9.1
EPSS 0.0050
EPSS Percentile 65.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-284
Status published
Products (2)
cisco/application_policy_infrastructure_controller < 3.2\(10e\)
cisco/cloud_application_policy_infrastructure_controller < 3.2\(10e\)
Published Aug 25, 2021
Tracked Since Feb 18, 2026