Vulnerability Bulletins

Cisco Application Policy Infrastructure Controller Enterprise Module Unauthorized Access Vulnerability

   
Affected software Cisco
 
A vulnerability in the application programming interface (API) of Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) could allow an unauthenticated, remote attacker to create false system notifications for administrators.The vulnerability is due to insufficient protection of API functions. An attacker could exploit this vulnerability by sending modified attribute-value pairs back to the affected system. An exploit could allow the attacker to trick an administrative

More info:

http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160428-apic?vs_f=Cisco%20Security%20Advisory&vs_cat=Security%20Intelligence&vs_type=RSS&vs_p=Cisco%20Application%20Policy%20Infrastructure%20Controller%20Enterprise%20Mod