Cisco ≫ Application Policy Infrastructure Controller Enterprise Module
7 vulnerabilities found.
- EPSS 1.53%
- Published 15.08.2018 20:29:01
- Last modified 21.11.2024 03:38:12
A vulnerability in the CronJob scheduler API of Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to perform a command injection attack. The vulnerability is due to incorrect input validation of user-suppli...
CVE-2018-0368
- EPSS 0.06%
- Published 16.07.2018 17:29:00
- Last modified 21.11.2024 03:38:04
A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an authenticated, local attacker to access sensitive information on an affected system. The vulnerability is due to insufficient security restrictions imposed by the affec...
CVE-2017-12262
- EPSS 0.6%
- Published 02.11.2017 16:29:00
- Last modified 20.04.2025 01:37:25
A vulnerability within the firewall configuration of the Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) could allow an unauthenticated, adjacent attacker to gain privileged access to services only available on the inte...
CVE-2016-1365
- EPSS 0.99%
- Published 18.08.2016 19:59:00
- Last modified 12.04.2025 10:46:40
The Grapevine update process in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.0 allows remote authenticated users to execute arbitrary commands as root via a crafted upgrade parameter, aka Bug ID CSCux15507.
CVE-2016-1318
- EPSS 0.25%
- Published 09.02.2016 03:59:01
- Last modified 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.1 allows remote attackers to inject arbitrary web script or HTML via crafted markup data, aka Bug ID CSCux15489.
CVE-2016-1305
- EPSS 0.25%
- Published 07.02.2016 11:59:02
- Last modified 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving HTML entities, aka Bug ID CSCux15511.
CVE-2015-6337
- EPSS 0.25%
- Published 26.01.2016 05:59:00
- Last modified 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.0.10 allows remote attackers to inject arbitrary web script or HTML via a crafted hostname in an SNMP response, aka Bug ID CS...