Privilege Escalation in Cisco Application Policy Infrastructure Controller
CVE-2017-6768
Key Information:
- Vendor
Cisco
- Vendor
- CVE Published:
- 17 August 2017
What is CVE-2017-6768?
A privilege escalation vulnerability exists in the Cisco Application Policy Infrastructure Controller (APIC) devices due to improperly validated library paths in certain executable system files. An authenticated local attacker can exploit this by loading a malicious library after authenticating on the device, allowing them to escalate their privileges to root level. This could enable full control over the device. Affected versions include specific releases in the 1.1, 1.2, 1.3, and 2.0 series, leading to potential severe compromise if exploited.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Application Policy Infrastructure Controller (APIC) 1.1(0.920a), 1.1(1j), 1.1(3f)
Application Policy Infrastructure Controller (APIC) 1.2 Base, 1.2(2), 1.2(3), 1.2.2
Application Policy Infrastructure Controller (APIC) 1.3(1), 1.3(2), 1.3(2f)
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved