Cisco ≫ Application Policy Infrastructure Controller Enterprise Module
7 Schwachstellen gefunden.
- EPSS 1.53%
- Veröffentlicht 15.08.2018 20:29:01
- Zuletzt bearbeitet 21.11.2024 03:38:12
A vulnerability in the CronJob scheduler API of Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to perform a command injection attack. The vulnerability is due to incorrect input validation of user-suppli...
CVE-2018-0368
- EPSS 0.06%
- Veröffentlicht 16.07.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:38:04
A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an authenticated, local attacker to access sensitive information on an affected system. The vulnerability is due to insufficient security restrictions imposed by the affec...
CVE-2017-12262
- EPSS 0.6%
- Veröffentlicht 02.11.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
A vulnerability within the firewall configuration of the Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) could allow an unauthenticated, adjacent attacker to gain privileged access to services only available on the inte...
CVE-2016-1365
- EPSS 0.99%
- Veröffentlicht 18.08.2016 19:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Grapevine update process in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.0 allows remote authenticated users to execute arbitrary commands as root via a crafted upgrade parameter, aka Bug ID CSCux15507.
CVE-2016-1318
- EPSS 0.25%
- Veröffentlicht 09.02.2016 03:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.1 allows remote attackers to inject arbitrary web script or HTML via crafted markup data, aka Bug ID CSCux15489.
CVE-2016-1305
- EPSS 0.25%
- Veröffentlicht 07.02.2016 11:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving HTML entities, aka Bug ID CSCux15511.
CVE-2015-6337
- EPSS 0.25%
- Veröffentlicht 26.01.2016 05:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.0.10 allows remote attackers to inject arbitrary web script or HTML via a crafted hostname in an SNMP response, aka Bug ID CS...