Database/Control plane, storage & DevOps
Cisco ACI Multi-Site Orchestrator (Application Services Engine): Complete unauthenticated authentication bypass on the
Impact
Complete unauthenticated authentication bypass on the controller that programs policy across every ACI site. Whoever gets this owns the tenant separation model for the entire multi-site fabric — they can write EPG and contract policy that stitches any tenant to any other. It is a 10.0 for a reason.
Who can reach it
Unauthenticated, remote — anything that can reach the MSO API endpoint. If the orchestrator's management interface is on a flat ops network, that is a very large set of machines.
What to do
Upgrade the MSO application. Application-level upgrade rather than a switch reload, so the data plane stays up — but treat any pre-patch exposure as a policy compromise and re-audit every contract and EPG binding afterwards, which is the real cost.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.