GPU VulnDB

Database/Control plane, storage & DevOps

Cisco APIC / Cloud APIC (API endpoint): Unauthenticated arbitrary file read and write on the APIC

CVE-2021-1577Control plane, storage & DevOpscurated

Impact

Unauthenticated arbitrary file read and write on the APIC — the ACI fabric controller. File write on the controller is effectively fabric takeover: you can plant credentials, alter policy state, and reprogram forwarding for every tenant on the pod.

Who can reach it

Unauthenticated, remote to the APIC's API endpoint. No credentials.

What to do

APIC software upgrade across the controller cluster (rolling, one APIC at a time, fabric keeps forwarding). Restrict APIC API reachability to a dedicated management network as a durable control — a config change you should make regardless of this CVE.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.