Access Control Bypass in Cisco APIC Devices and Nexus 9000 Switches
CVE-2016-1302
8.8HIGH
Key Information:
- Vendor
Samsung
- Vendor
- CVE Published:
- 7 February 2016
What is CVE-2016-1302?
Cisco Application Policy Infrastructure Controller (APIC) devices and Nexus 9000 ACI Mode switches are susceptible to an access control vulnerability that allows remote authenticated users to bypass intended Role-Based Access Control (RBAC) restrictions. This can be exploited through crafted REST requests, potentially leading to unauthorized access to sensitive resources and functionality. Users running versions prior to 1.0(3h) and 1.1(1j) for APIC, as well as those with Nexus 9000 devices on software versions before 11.0(3h) and 11.1(1j), are at risk. It is crucial for users to update their systems to mitigate this vulnerability.