The vulnerability is due to eligibility logic in the RBAC processing code. An authenticated user could exploit this vulnerability by sending specially crafted representational state transfer (REST) requests to the APIC. An exploit could allow the authenticated user to make configuration changes to the APIC beyond the configured privilege for their role.
Cisco has released software updates that address this vulnerability.
This advisory is available at the following link: http://ift.tt/1SsZTKQ
from Cisco Security Advisory http://ift.tt/1SsZTKQ
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.