Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.0(3h) and 1.1 before 1.1(1j) and Nexus 9000 ACI Mode switches with software before 11.0(3h) and 11.1 before 11.1(1j) allow remote authenticated users to bypass intended RBAC restrictions via crafted REST requests, aka Bug ID CSCut12998.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Cisco
Subscribe
|
Nexus 92160yc-x
Subscribe
Nexus 92304qc
Subscribe
Nexus 9236c
Subscribe
Nexus 9272q
Subscribe
Nexus 93108tc-ex
Subscribe
Nexus 93120tx
Subscribe
Nexus 93128tx
Subscribe
Nexus 93180yc-ex
Subscribe
Nexus 9332pq
Subscribe
Nexus 9336pq Aci Spine
Subscribe
Nexus 9372px
Subscribe
Nexus 9372tx
Subscribe
Nexus 9396px
Subscribe
Nexus 9396tx
Subscribe
Nexus 9504
Subscribe
Nexus 9508
Subscribe
Nexus 9516
Subscribe
Nx-os
Subscribe
|
|
Samsung
Subscribe
|
X14j Firmware
Subscribe
|
|
Sun
Subscribe
|
Opensolaris
Subscribe
|
|
Zyxel
Subscribe
|
Gs1900-10hp Firmware
Subscribe
|
|
Zzinc
Subscribe
|
Keymouse Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2016-2401 | Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.0(3h) and 1.1 before 1.1(1j) and Nexus 9000 ACI Mode switches with software before 11.0(3h) and 11.1 before 11.1(1j) allow remote authenticated users to bypass intended RBAC restrictions via crafted REST requests, aka Bug ID CSCut12998. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-08-05T22:48:13.687Z
Reserved: 2016-01-04T00:00:00
Link: CVE-2016-1302
No data.
Status : Deferred
Published: 2016-02-07T11:59:01.943
Modified: 2025-04-12T10:46:40.837
Link: CVE-2016-1302
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD