GPU VulnDB

Database/Control plane, storage & DevOps

Cisco ACI Multi-Site Orchestrator (Application Services Engine): Complete unauthenticated authentication bypass on the

CVE-2021-1388Control plane, storage & DevOpscurated

Impact

Complete unauthenticated authentication bypass on the controller that programs policy across every ACI site. Whoever gets this owns the tenant separation model for the entire multi-site fabric — they can write EPG and contract policy that stitches any tenant to any other. It is a 10.0 for a reason.

Who can reach it

Unauthenticated, remote — anything that can reach the MSO API endpoint. If the orchestrator's management interface is on a flat ops network, that is a very large set of machines.

What to do

Upgrade the MSO application. Application-level upgrade rather than a switch reload, so the data plane stays up — but treat any pre-patch exposure as a policy compromise and re-audit every contract and EPG binding afterwards, which is the real cost.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.