exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Cisco Security Advisory 20150722-apic

Cisco Security Advisory 20150722-apic
Posted Jul 22, 2015
Authored by Cisco Systems | Site cisco.com

Cisco Security Advisory - A vulnerability in the cluster management configuration of the Cisco Application Policy Infrastructure Controller (APIC) and the Cisco Nexus 9000 Series ACI Mode Switch could allow an authenticated, remote attacker to access the APIC as the root user. The vulnerability is due to improper implementation of access controls in the APIC filesystem. An attacker could exploit this vulnerability by accessing the cluster management configuration of the APIC. An exploit could allow the attacker to gain access to the APIC as the root user and perform root-level commands. Cisco has released software updates that address this vulnerability.

tags | advisory, remote, root
systems | cisco
SHA-256 | fafd7eb09a16ca913cb45419d8ba5f8ceb303b8a96173884be5dd66938a190c9

Cisco Security Advisory 20150722-apic

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Cisco Security Advisory: Cisco Application Policy Infrastructure Controller Access Control Vulnerability

Advisory ID: cisco-sa-20150722-apic

Revision 1.0

For Public Release 2015 July 22 16:00 UTC (GMT)

-----------------------------------------------------------------------------------------

Summary
=======

A vulnerability in the cluster management configuration of the Cisco Application Policy Infrastructure Controller (APIC) and the Cisco Nexus 9000 Series ACI Mode Switch could allow an authenticated, remote attacker to access the APIC as the root user.

The vulnerability is due to improper implementation of access controls in the APIC filesystem. An attacker could exploit this vulnerability by accessing the cluster management configuration of the APIC. An exploit could allow the attacker to gain access to the APIC as the root user and perform root-level commands.

Cisco has released software updates that address this vulnerability.

This advisory is available at the following link:
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150722-apic
-----BEGIN PGP SIGNATURE-----
Comment: GPGTools - http://gpgtools.org

iQIcBAEBCgAGBQJVrtbDAAoJEIpI1I6i1Mx3btoP/2ab0rglGwG9K0DZbKgg/uk0
v7hAZl9ZAjFJj61v0R5byP286xSMvn6MXz1Jr44epjPF2a3ej4aR01gyTvMO6DUD
UGmheZFvsmbrfd2sqRFHF/x1g2bOIdYq4i7z0BVP9YXJ4T3WR5FE3DxXt1VqZiTK
ywNIWfwDv73LwEJrsSa+z3Z7pT3LxPBavBgtvzjUDizqW8zrpGS+KeMw8ol4Xz4p
VVMtTo4DfXphaC2UiAtzP4UnJl3AQXCKNzYRAU56XxrqlkgQxQg2ZnrP7fJvTXET
U2eHf4pQXkG2+BKl2gCc2onQqdeXmitlFyTlGIZbiJ/iLAY6oxy3SUT4gVZdMUXf
O7BU5rA99maZq65+Ziu/bKuCe1AilKSg4TiSjhu0fIKbiMu1b9mqrgv4n9KaTtWY
UdpiKJGtQQQrrI6r1gZeEIZ2K2/ybMBT3nRm+avD+omRa4R5HX1V+BhWksPF3eA6
H+xtN/pBIBs7ecahWRcdqu9pY76Re/JCtIrlLCHNfBMi6PPEcnUjaE4RpWaumnBO
sCPEp8t0leACiCP11M2ZjMFm6GfrTDTF04AYP+VkAWYXNcfNSxp6MoC4Ee1ygb1/
2ywXDFpFPj4XIwKIgyE6k76ND5r2WuK1e1VEuW4jikGYeeCQ3nmrJFHDc/mmyAum
0emrgf0YLmkfmXrYzv0u
=zm4G
-----END PGP SIGNATURE-----
Login or Register to add favorites

File Archive:

March 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Mar 1st
    16 Files
  • 2
    Mar 2nd
    0 Files
  • 3
    Mar 3rd
    0 Files
  • 4
    Mar 4th
    32 Files
  • 5
    Mar 5th
    28 Files
  • 6
    Mar 6th
    42 Files
  • 7
    Mar 7th
    17 Files
  • 8
    Mar 8th
    13 Files
  • 9
    Mar 9th
    0 Files
  • 10
    Mar 10th
    0 Files
  • 11
    Mar 11th
    15 Files
  • 12
    Mar 12th
    19 Files
  • 13
    Mar 13th
    21 Files
  • 14
    Mar 14th
    38 Files
  • 15
    Mar 15th
    15 Files
  • 16
    Mar 16th
    0 Files
  • 17
    Mar 17th
    0 Files
  • 18
    Mar 18th
    10 Files
  • 19
    Mar 19th
    32 Files
  • 20
    Mar 20th
    46 Files
  • 21
    Mar 21st
    16 Files
  • 22
    Mar 22nd
    13 Files
  • 23
    Mar 23rd
    0 Files
  • 24
    Mar 24th
    0 Files
  • 25
    Mar 25th
    12 Files
  • 26
    Mar 26th
    31 Files
  • 27
    Mar 27th
    19 Files
  • 28
    Mar 28th
    42 Files
  • 29
    Mar 29th
    0 Files
  • 30
    Mar 30th
    0 Files
  • 31
    Mar 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close