Vulnslist

Cisco vulnerabilities by product, model, software, and advisory.

CVE-2021-1388

A vulnerability in an API endpoint of Cisco ACI Multi-Site Orchestrator (MSO) installed on the Application Services Engine could allow an unauthenticated, remote attacker to bypass authentication on an affected device. The vulnerability is due to improper token validation on a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted request to the affected API. A successful exploit could allow the attacker to receive a token with administrator-level privileges that could be used to authenticate to the API on affected MSO and managed Cisco Application Policy Infrastructure Controller (APIC) devices.

SeverityCRITICAL
CVSS10.0
CWECWE-269
KEV
Published
Modified

Related Products

Product Advisory Evidence
Cisco Nexus Dashboard Orchestrator cisco-sa-mso-authbyp-bb5GmBQv Cisco OpenVuln
Cisco Nexus Dashboard cisco-sa-mso-authbyp-bb5GmBQv Cisco OpenVuln
Cisco ACI Multi-Site Orchestrator Software cisco-sa-mso-authbyp-bb5GmBQv Cisco OpenVuln