CVE-2024-20279 (GCVE-0-2024-20279)
Vulnerability from cvelistv5
Published
2024-08-28 16:19
Modified
2024-08-28 17:54
CWE
  • CWE-284 - Improper Access Control
Summary
A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to modify the behavior of default system policies, such as quality of service (QoS) policies, on an affected system. This vulnerability is due to improper access control when restricted security domains are used to implement multi-tenancy. An attacker with a valid user account associated with a restricted security domain could exploit this vulnerability. A successful exploit could allow the attacker to read, modify, or delete child policies created under default system policies, which are implicitly used by all tenants in the fabric, resulting in disruption of network traffic. Exploitation is not possible for policies under tenants that an attacker has no authorization to access.
Impacted products
Vendor Product Version
Cisco Cisco Application Policy Infrastructure Controller (APIC) Version: 3.2(8d)
Version: 2.2(1o)
Version: 1.2(2h)
Version: 2.2(2i)
Version: 1.2(1k)
Version: 2.2(1k)
Version: 3.1(2m)
Version: 3.2(1m)
Version: 3.2(5e)
Version: 4.1(2m)
Version: 3.2(41d)
Version: 1.1(1o)
Version: 1.2(1m)
Version: 1.2(2j)
Version: 2.2(4r)
Version: 2.2(3j)
Version: 1.1(3f)
Version: 2.2(2f)
Version: 1.1(4m)
Version: 2.2(2k)
Version: 2.1(1i)
Version: 2.0(1p)
Version: 3.1(2p)
Version: 3.2(3s)
Version: 4.0(3c)
Version: 1.1(4e)
Version: 4.1(1k)
Version: 2.2(4f)
Version: 2.1(3h)
Version: 3.2(4d)
Version: 2.0(1n)
Version: 2.0(1m)
Version: 2.0(1r)
Version: 2.1(2e)
Version: 4.2(2e)
Version: 4.2(3j)
Version: 4.2(3n)
Version: 2.0(1l)
Version: 2.2(2e)
Version: 2.2(3r)
Version: 3.0(2k)
Version: 2.1(3g)
Version: 4.0(1h)
Version: 2.0(1o)
Version: 2.2(3p)
Version: 1.2(3e)
Version: 2.2(3s)
Version: 2.0(2g)
Version: 4.1(1l)
Version: 3.2(9f)
Version: 4.2(3l)
Version: 4.2(2g)
Version: 1.2(3c)
Version: 3.2(7k)
Version: 1.3(2h)
Version: 3.2(9b)
Version: 1.3(2k)
Version: 3.1(2t)
Version: 1.1(2h)
Version: 3.2(3j)
Version: 2.1(2k)
Version: 2.3(1f)
Version: 1.2(3h)
Version: 3.0(1i)
Version: 4.1(2u)
Version: 4.2(1l)
Version: 4.1(1a)
Version: 4.0(3d)
Version: 1.1(4l)
Version: 2.3(1i)
Version: 3.1(2q)
Version: 3.2(4e)
Version: 4.1(1i)
Version: 3.1(1i)
Version: 2.0(2m)
Version: 3.0(2h)
Version: 2.2(2q)
Version: 2.3(1l)
Version: 1.3(1h)
Version: 3.0(2n)
Version: 3.2(5f)
Version: 1.2(1h)
Version: 3.2(1l)
Version: 4.2(1i)
Version: 4.1(2o)
Version: 1.2(1i)
Version: 1.3(1j)
Version: 2.1(1h)
Version: 2.0(2l)
Version: 2.0(2h)
Version: 1.2(2g)
Version: 3.0(1k)
Version: 4.2(1g)
Version: 2.1(2g)
Version: 2.0(1q)
Version: 1.1(1j)
Version: 4.1(2g)
Version: 1.1(1r)
Version: 4.2(2f)
Version: 3.2(6i)
Version: 1.3(1g)
Version: 1.3(2j)
Version: 1.3(2i)
Version: 2.0(2o)
Version: 2.2(4q)
Version: 2.3(1o)
Version: 3.2(3i)
Version: 2.2(2j)
Version: 1.1(1d)
Version: 2.0(2n)
Version: 2.2(3t)
Version: 3.2(3n)
Version: 1.1(4g)
Version: 4.1(2x)
Version: 3.2(5d)
Version: 3.1(2o)
Version: 1.2(2i)
Version: 2.1(2f)
Version: 1.3(2f)
Version: 4.2(3q)
Version: 4.1(1j)
Version: 2.0(2f)
Version: 2.3(1e)
Version: 1.1(1s)
Version: 3.1(2v)
Version: 4.1(2w)
Version: 1.1(4i)
Version: 3.1(2u)
Version: 1.1(4f)
Version: 3.0(2m)
Version: 2.0(1k)
Version: 3.2(2o)
Version: 3.2(3r)
Version: 1.1(2i)
Version: 4.0(2c)
Version: 1.3(1i)
Version: 4.1(2s)
Version: 3.2(7f)
Version: 1.2(3m)
Version: 3.2(3o)
Version: 3.1(2s)
Version: 3.2(2l)
Version: 4.2(1j)
Version: 2.3(1p)
Version: 2.1(4a)
Version: 1.1(1n)
Version: 2.2(1n)
Version: 2.2(4p)
Version: 2.1(3j)
Version: 4.2(4i)
Version: 3.2(9h)
Version: 5.0(1k)
Version: 4.2(4k)
Version: 5.0(1l)
Version: 5.0(2e)
Version: 4.2(4o)
Version: 4.2(4p)
Version: 5.0(2h)
Version: 4.2(5k)
Version: 4.2(5l)
Version: 4.2(5n)
Version: 5.1(1h)
Version: 4.2(6d)
Version: 5.1(2e)
Version: 4.2(6g)
Version: 4.2(6h)
Version: 5.1(3e)
Version: 3.2(10e)
Version: 4.2(6l)
Version: 4.2(7f)
Version: 5.1(4c)
Version: 4.2(6o)
Version: 5.2(1g)
Version: 5.2(2e)
Version: 4.2(7l)
Version: 3.2(10f)
Version: 5.2(2f)
Version: 5.2(2g)
Version: 4.2(7q)
Version: 5.2(2h)
Version: 5.2(3f)
Version: 5.2(3e)
Version: 5.2(3g)
Version: 4.2(7r)
Version: 4.2(7s)
Version: 5.2(4d)
Version: 5.2(4e)
Version: 4.2(7t)
Version: 5.2(5d)
Version: 3.2(10g)
Version: 5.2(5c)
Version: 6.0(1g)
Version: 4.2(7u)
Version: 5.2(5e)
Version: 5.2(4f)
Version: 5.2(6e)
Version: 6.0(1j)
Version: 5.2(6g)
Version: 5.2(7f)
Version: 4.2(7v)
Version: 5.2(7g)
Version: 6.0(2h)
Version: 4.2(7w)
Version: 5.2(6h)
Version: 5.2(4h)
Version: 5.2(8d)
Version: 6.0(2j)
Version: 5.2(8e)
Version: 6.0(3d)
Version: 6.0(3e)
Version: 5.2(8f)
Version: 5.2(8g)
Version: 5.3(1d)
Version: 5.2(8h)
Version: 6.0(4c)
Version: 5.3(2a)
Version: 5.2(8i)
Version: 6.0(5h)
Version: 5.3(2b)
Version: 6.0(3g)
Version: 6.0(5j)
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2024-20279",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-08-28T17:54:46.155615Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-08-28T17:54:51.419Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unknown",
          "product": "Cisco Application Policy Infrastructure Controller (APIC)",
          "vendor": "Cisco",
          "versions": [
            {
              "status": "affected",
              "version": "3.2(8d)"
            },
            {
              "status": "affected",
              "version": "2.2(1o)"
            },
            {
              "status": "affected",
              "version": "1.2(2h)"
            },
            {
              "status": "affected",
              "version": "2.2(2i)"
            },
            {
              "status": "affected",
              "version": "1.2(1k)"
            },
            {
              "status": "affected",
              "version": "2.2(1k)"
            },
            {
              "status": "affected",
              "version": "3.1(2m)"
            },
            {
              "status": "affected",
              "version": "3.2(1m)"
            },
            {
              "status": "affected",
              "version": "3.2(5e)"
            },
            {
              "status": "affected",
              "version": "4.1(2m)"
            },
            {
              "status": "affected",
              "version": "3.2(41d)"
            },
            {
              "status": "affected",
              "version": "1.1(1o)"
            },
            {
              "status": "affected",
              "version": "1.2(1m)"
            },
            {
              "status": "affected",
              "version": "1.2(2j)"
            },
            {
              "status": "affected",
              "version": "2.2(4r)"
            },
            {
              "status": "affected",
              "version": "2.2(3j)"
            },
            {
              "status": "affected",
              "version": "1.1(3f)"
            },
            {
              "status": "affected",
              "version": "2.2(2f)"
            },
            {
              "status": "affected",
              "version": "1.1(4m)"
            },
            {
              "status": "affected",
              "version": "2.2(2k)"
            },
            {
              "status": "affected",
              "version": "2.1(1i)"
            },
            {
              "status": "affected",
              "version": "2.0(1p)"
            },
            {
              "status": "affected",
              "version": "3.1(2p)"
            },
            {
              "status": "affected",
              "version": "3.2(3s)"
            },
            {
              "status": "affected",
              "version": "4.0(3c)"
            },
            {
              "status": "affected",
              "version": "1.1(4e)"
            },
            {
              "status": "affected",
              "version": "4.1(1k)"
            },
            {
              "status": "affected",
              "version": "2.2(4f)"
            },
            {
              "status": "affected",
              "version": "2.1(3h)"
            },
            {
              "status": "affected",
              "version": "3.2(4d)"
            },
            {
              "status": "affected",
              "version": "2.0(1n)"
            },
            {
              "status": "affected",
              "version": "2.0(1m)"
            },
            {
              "status": "affected",
              "version": "2.0(1r)"
            },
            {
              "status": "affected",
              "version": "2.1(2e)"
            },
            {
              "status": "affected",
              "version": "4.2(2e)"
            },
            {
              "status": "affected",
              "version": "4.2(3j)"
            },
            {
              "status": "affected",
              "version": "4.2(3n)"
            },
            {
              "status": "affected",
              "version": "2.0(1l)"
            },
            {
              "status": "affected",
              "version": "2.2(2e)"
            },
            {
              "status": "affected",
              "version": "2.2(3r)"
            },
            {
              "status": "affected",
              "version": "3.0(2k)"
            },
            {
              "status": "affected",
              "version": "2.1(3g)"
            },
            {
              "status": "affected",
              "version": "4.0(1h)"
            },
            {
              "status": "affected",
              "version": "2.0(1o)"
            },
            {
              "status": "affected",
              "version": "2.2(3p)"
            },
            {
              "status": "affected",
              "version": "1.2(3e)"
            },
            {
              "status": "affected",
              "version": "2.2(3s)"
            },
            {
              "status": "affected",
              "version": "2.0(2g)"
            },
            {
              "status": "affected",
              "version": "4.1(1l)"
            },
            {
              "status": "affected",
              "version": "3.2(9f)"
            },
            {
              "status": "affected",
              "version": "4.2(3l)"
            },
            {
              "status": "affected",
              "version": "4.2(2g)"
            },
            {
              "status": "affected",
              "version": "1.2(3c)"
            },
            {
              "status": "affected",
              "version": "3.2(7k)"
            },
            {
              "status": "affected",
              "version": "1.3(2h)"
            },
            {
              "status": "affected",
              "version": "3.2(9b)"
            },
            {
              "status": "affected",
              "version": "1.3(2k)"
            },
            {
              "status": "affected",
              "version": "3.1(2t)"
            },
            {
              "status": "affected",
              "version": "1.1(2h)"
            },
            {
              "status": "affected",
              "version": "3.2(3j)"
            },
            {
              "status": "affected",
              "version": "2.1(2k)"
            },
            {
              "status": "affected",
              "version": "2.3(1f)"
            },
            {
              "status": "affected",
              "version": "1.2(3h)"
            },
            {
              "status": "affected",
              "version": "3.0(1i)"
            },
            {
              "status": "affected",
              "version": "4.1(2u)"
            },
            {
              "status": "affected",
              "version": "4.2(1l)"
            },
            {
              "status": "affected",
              "version": "4.1(1a)"
            },
            {
              "status": "affected",
              "version": "4.0(3d)"
            },
            {
              "status": "affected",
              "version": "1.1(4l)"
            },
            {
              "status": "affected",
              "version": "2.3(1i)"
            },
            {
              "status": "affected",
              "version": "3.1(2q)"
            },
            {
              "status": "affected",
              "version": "3.2(4e)"
            },
            {
              "status": "affected",
              "version": "4.1(1i)"
            },
            {
              "status": "affected",
              "version": "3.1(1i)"
            },
            {
              "status": "affected",
              "version": "2.0(2m)"
            },
            {
              "status": "affected",
              "version": "3.0(2h)"
            },
            {
              "status": "affected",
              "version": "2.2(2q)"
            },
            {
              "status": "affected",
              "version": "2.3(1l)"
            },
            {
              "status": "affected",
              "version": "1.3(1h)"
            },
            {
              "status": "affected",
              "version": "3.0(2n)"
            },
            {
              "status": "affected",
              "version": "3.2(5f)"
            },
            {
              "status": "affected",
              "version": "1.2(1h)"
            },
            {
              "status": "affected",
              "version": "3.2(1l)"
            },
            {
              "status": "affected",
              "version": "4.2(1i)"
            },
            {
              "status": "affected",
              "version": "4.1(2o)"
            },
            {
              "status": "affected",
              "version": "1.2(1i)"
            },
            {
              "status": "affected",
              "version": "1.3(1j)"
            },
            {
              "status": "affected",
              "version": "2.1(1h)"
            },
            {
              "status": "affected",
              "version": "2.0(2l)"
            },
            {
              "status": "affected",
              "version": "2.0(2h)"
            },
            {
              "status": "affected",
              "version": "1.2(2g)"
            },
            {
              "status": "affected",
              "version": "3.0(1k)"
            },
            {
              "status": "affected",
              "version": "4.2(1g)"
            },
            {
              "status": "affected",
              "version": "2.1(2g)"
            },
            {
              "status": "affected",
              "version": "2.0(1q)"
            },
            {
              "status": "affected",
              "version": "1.1(1j)"
            },
            {
              "status": "affected",
              "version": "4.1(2g)"
            },
            {
              "status": "affected",
              "version": "1.1(1r)"
            },
            {
              "status": "affected",
              "version": "4.2(2f)"
            },
            {
              "status": "affected",
              "version": "3.2(6i)"
            },
            {
              "status": "affected",
              "version": "1.3(1g)"
            },
            {
              "status": "affected",
              "version": "1.3(2j)"
            },
            {
              "status": "affected",
              "version": "1.3(2i)"
            },
            {
              "status": "affected",
              "version": "2.0(2o)"
            },
            {
              "status": "affected",
              "version": "2.2(4q)"
            },
            {
              "status": "affected",
              "version": "2.3(1o)"
            },
            {
              "status": "affected",
              "version": "3.2(3i)"
            },
            {
              "status": "affected",
              "version": "2.2(2j)"
            },
            {
              "status": "affected",
              "version": "1.1(1d)"
            },
            {
              "status": "affected",
              "version": "2.0(2n)"
            },
            {
              "status": "affected",
              "version": "2.2(3t)"
            },
            {
              "status": "affected",
              "version": "3.2(3n)"
            },
            {
              "status": "affected",
              "version": "1.1(4g)"
            },
            {
              "status": "affected",
              "version": "4.1(2x)"
            },
            {
              "status": "affected",
              "version": "3.2(5d)"
            },
            {
              "status": "affected",
              "version": "3.1(2o)"
            },
            {
              "status": "affected",
              "version": "1.2(2i)"
            },
            {
              "status": "affected",
              "version": "2.1(2f)"
            },
            {
              "status": "affected",
              "version": "1.3(2f)"
            },
            {
              "status": "affected",
              "version": "4.2(3q)"
            },
            {
              "status": "affected",
              "version": "4.1(1j)"
            },
            {
              "status": "affected",
              "version": "2.0(2f)"
            },
            {
              "status": "affected",
              "version": "2.3(1e)"
            },
            {
              "status": "affected",
              "version": "1.1(1s)"
            },
            {
              "status": "affected",
              "version": "3.1(2v)"
            },
            {
              "status": "affected",
              "version": "4.1(2w)"
            },
            {
              "status": "affected",
              "version": "1.1(4i)"
            },
            {
              "status": "affected",
              "version": "3.1(2u)"
            },
            {
              "status": "affected",
              "version": "1.1(4f)"
            },
            {
              "status": "affected",
              "version": "3.0(2m)"
            },
            {
              "status": "affected",
              "version": "2.0(1k)"
            },
            {
              "status": "affected",
              "version": "3.2(2o)"
            },
            {
              "status": "affected",
              "version": "3.2(3r)"
            },
            {
              "status": "affected",
              "version": "1.1(2i)"
            },
            {
              "status": "affected",
              "version": "4.0(2c)"
            },
            {
              "status": "affected",
              "version": "1.3(1i)"
            },
            {
              "status": "affected",
              "version": "4.1(2s)"
            },
            {
              "status": "affected",
              "version": "3.2(7f)"
            },
            {
              "status": "affected",
              "version": "1.2(3m)"
            },
            {
              "status": "affected",
              "version": "3.2(3o)"
            },
            {
              "status": "affected",
              "version": "3.1(2s)"
            },
            {
              "status": "affected",
              "version": "3.2(2l)"
            },
            {
              "status": "affected",
              "version": "4.2(1j)"
            },
            {
              "status": "affected",
              "version": "2.3(1p)"
            },
            {
              "status": "affected",
              "version": "2.1(4a)"
            },
            {
              "status": "affected",
              "version": "1.1(1n)"
            },
            {
              "status": "affected",
              "version": "2.2(1n)"
            },
            {
              "status": "affected",
              "version": "2.2(4p)"
            },
            {
              "status": "affected",
              "version": "2.1(3j)"
            },
            {
              "status": "affected",
              "version": "4.2(4i)"
            },
            {
              "status": "affected",
              "version": "3.2(9h)"
            },
            {
              "status": "affected",
              "version": "5.0(1k)"
            },
            {
              "status": "affected",
              "version": "4.2(4k)"
            },
            {
              "status": "affected",
              "version": "5.0(1l)"
            },
            {
              "status": "affected",
              "version": "5.0(2e)"
            },
            {
              "status": "affected",
              "version": "4.2(4o)"
            },
            {
              "status": "affected",
              "version": "4.2(4p)"
            },
            {
              "status": "affected",
              "version": "5.0(2h)"
            },
            {
              "status": "affected",
              "version": "4.2(5k)"
            },
            {
              "status": "affected",
              "version": "4.2(5l)"
            },
            {
              "status": "affected",
              "version": "4.2(5n)"
            },
            {
              "status": "affected",
              "version": "5.1(1h)"
            },
            {
              "status": "affected",
              "version": "4.2(6d)"
            },
            {
              "status": "affected",
              "version": "5.1(2e)"
            },
            {
              "status": "affected",
              "version": "4.2(6g)"
            },
            {
              "status": "affected",
              "version": "4.2(6h)"
            },
            {
              "status": "affected",
              "version": "5.1(3e)"
            },
            {
              "status": "affected",
              "version": "3.2(10e)"
            },
            {
              "status": "affected",
              "version": "4.2(6l)"
            },
            {
              "status": "affected",
              "version": "4.2(7f)"
            },
            {
              "status": "affected",
              "version": "5.1(4c)"
            },
            {
              "status": "affected",
              "version": "4.2(6o)"
            },
            {
              "status": "affected",
              "version": "5.2(1g)"
            },
            {
              "status": "affected",
              "version": "5.2(2e)"
            },
            {
              "status": "affected",
              "version": "4.2(7l)"
            },
            {
              "status": "affected",
              "version": "3.2(10f)"
            },
            {
              "status": "affected",
              "version": "5.2(2f)"
            },
            {
              "status": "affected",
              "version": "5.2(2g)"
            },
            {
              "status": "affected",
              "version": "4.2(7q)"
            },
            {
              "status": "affected",
              "version": "5.2(2h)"
            },
            {
              "status": "affected",
              "version": "5.2(3f)"
            },
            {
              "status": "affected",
              "version": "5.2(3e)"
            },
            {
              "status": "affected",
              "version": "5.2(3g)"
            },
            {
              "status": "affected",
              "version": "4.2(7r)"
            },
            {
              "status": "affected",
              "version": "4.2(7s)"
            },
            {
              "status": "affected",
              "version": "5.2(4d)"
            },
            {
              "status": "affected",
              "version": "5.2(4e)"
            },
            {
              "status": "affected",
              "version": "4.2(7t)"
            },
            {
              "status": "affected",
              "version": "5.2(5d)"
            },
            {
              "status": "affected",
              "version": "3.2(10g)"
            },
            {
              "status": "affected",
              "version": "5.2(5c)"
            },
            {
              "status": "affected",
              "version": "6.0(1g)"
            },
            {
              "status": "affected",
              "version": "4.2(7u)"
            },
            {
              "status": "affected",
              "version": "5.2(5e)"
            },
            {
              "status": "affected",
              "version": "5.2(4f)"
            },
            {
              "status": "affected",
              "version": "5.2(6e)"
            },
            {
              "status": "affected",
              "version": "6.0(1j)"
            },
            {
              "status": "affected",
              "version": "5.2(6g)"
            },
            {
              "status": "affected",
              "version": "5.2(7f)"
            },
            {
              "status": "affected",
              "version": "4.2(7v)"
            },
            {
              "status": "affected",
              "version": "5.2(7g)"
            },
            {
              "status": "affected",
              "version": "6.0(2h)"
            },
            {
              "status": "affected",
              "version": "4.2(7w)"
            },
            {
              "status": "affected",
              "version": "5.2(6h)"
            },
            {
              "status": "affected",
              "version": "5.2(4h)"
            },
            {
              "status": "affected",
              "version": "5.2(8d)"
            },
            {
              "status": "affected",
              "version": "6.0(2j)"
            },
            {
              "status": "affected",
              "version": "5.2(8e)"
            },
            {
              "status": "affected",
              "version": "6.0(3d)"
            },
            {
              "status": "affected",
              "version": "6.0(3e)"
            },
            {
              "status": "affected",
              "version": "5.2(8f)"
            },
            {
              "status": "affected",
              "version": "5.2(8g)"
            },
            {
              "status": "affected",
              "version": "5.3(1d)"
            },
            {
              "status": "affected",
              "version": "5.2(8h)"
            },
            {
              "status": "affected",
              "version": "6.0(4c)"
            },
            {
              "status": "affected",
              "version": "5.3(2a)"
            },
            {
              "status": "affected",
              "version": "5.2(8i)"
            },
            {
              "status": "affected",
              "version": "6.0(5h)"
            },
            {
              "status": "affected",
              "version": "5.3(2b)"
            },
            {
              "status": "affected",
              "version": "6.0(3g)"
            },
            {
              "status": "affected",
              "version": "6.0(5j)"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to modify the behavior of default system policies, such as quality of service (QoS) policies, on an affected system.\u0026nbsp;This vulnerability is due to improper access control when restricted security domains are used to implement multi-tenancy. An attacker with a valid user account associated with a restricted security domain could exploit this vulnerability. A successful exploit could allow the attacker to read, modify, or delete child policies created under default system policies, which are implicitly used by all tenants in the fabric, resulting in disruption of network traffic. Exploitation is not possible for policies under tenants that an attacker has no authorization to access."
        }
      ],
      "exploits": [
        {
          "lang": "en",
          "value": "The Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "format": "cvssV3_1"
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-284",
              "description": "Improper Access Control",
              "lang": "en",
              "type": "cwe"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2024-08-28T16:19:08.343Z",
        "orgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
        "shortName": "cisco"
      },
      "references": [
        {
          "name": "cisco-sa-apic-cousmo-uBpBYGbq",
          "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apic-cousmo-uBpBYGbq"
        }
      ],
      "source": {
        "advisory": "cisco-sa-apic-cousmo-uBpBYGbq",
        "defects": [
          "CSCwe67288"
        ],
        "discovery": "INTERNAL"
      },
      "title": "Cisco Application Policy Infrastructure Controller Unauthorized Policy Actions Vulnerability"
    }
  },
  "cveMetadata": {
    "assignerOrgId": "d1c1063e-7a18-46af-9102-31f8928bc633",
    "assignerShortName": "cisco",
    "cveId": "CVE-2024-20279",
    "datePublished": "2024-08-28T16:19:08.343Z",
    "dateReserved": "2023-11-08T15:08:07.625Z",
    "dateUpdated": "2024-08-28T17:54:51.419Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2024-20279\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2024-08-28T17:54:46.155615Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2024-08-28T17:53:58.950Z\"}}], \"cna\": {\"title\": \"Cisco Application Policy Infrastructure Controller Unauthorized Policy Actions Vulnerability\", \"source\": {\"defects\": [\"CSCwe67288\"], \"advisory\": \"cisco-sa-apic-cousmo-uBpBYGbq\", \"discovery\": \"INTERNAL\"}, \"metrics\": [{\"format\": \"cvssV3_1\", \"cvssV3_1\": {\"scope\": \"UNCHANGED\", \"version\": \"3.1\", \"baseScore\": 4.3, \"attackVector\": \"NETWORK\", \"baseSeverity\": \"MEDIUM\", \"vectorString\": \"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N\", \"integrityImpact\": \"LOW\", \"userInteraction\": \"NONE\", \"attackComplexity\": \"LOW\", \"availabilityImpact\": \"NONE\", \"privilegesRequired\": \"LOW\", \"confidentialityImpact\": \"NONE\"}}], \"affected\": [{\"vendor\": \"Cisco\", \"product\": \"Cisco Application Policy Infrastructure Controller (APIC)\", \"versions\": [{\"status\": \"affected\", \"version\": \"3.2(8d)\"}, {\"status\": \"affected\", \"version\": \"2.2(1o)\"}, {\"status\": \"affected\", \"version\": \"1.2(2h)\"}, {\"status\": \"affected\", \"version\": \"2.2(2i)\"}, {\"status\": \"affected\", \"version\": \"1.2(1k)\"}, {\"status\": \"affected\", \"version\": \"2.2(1k)\"}, {\"status\": \"affected\", \"version\": \"3.1(2m)\"}, {\"status\": \"affected\", \"version\": \"3.2(1m)\"}, {\"status\": \"affected\", \"version\": \"3.2(5e)\"}, {\"status\": \"affected\", \"version\": \"4.1(2m)\"}, {\"status\": \"affected\", \"version\": \"3.2(41d)\"}, {\"status\": \"affected\", \"version\": \"1.1(1o)\"}, {\"status\": \"affected\", \"version\": \"1.2(1m)\"}, {\"status\": \"affected\", \"version\": \"1.2(2j)\"}, {\"status\": \"affected\", \"version\": \"2.2(4r)\"}, {\"status\": \"affected\", \"version\": \"2.2(3j)\"}, {\"status\": \"affected\", \"version\": \"1.1(3f)\"}, {\"status\": \"affected\", \"version\": \"2.2(2f)\"}, {\"status\": \"affected\", \"version\": \"1.1(4m)\"}, {\"status\": \"affected\", \"version\": \"2.2(2k)\"}, {\"status\": \"affected\", \"version\": \"2.1(1i)\"}, {\"status\": \"affected\", \"version\": \"2.0(1p)\"}, {\"status\": \"affected\", \"version\": \"3.1(2p)\"}, {\"status\": \"affected\", \"version\": \"3.2(3s)\"}, {\"status\": \"affected\", \"version\": \"4.0(3c)\"}, {\"status\": \"affected\", \"version\": \"1.1(4e)\"}, {\"status\": \"affected\", \"version\": \"4.1(1k)\"}, {\"status\": \"affected\", \"version\": \"2.2(4f)\"}, {\"status\": \"affected\", \"version\": \"2.1(3h)\"}, {\"status\": \"affected\", \"version\": \"3.2(4d)\"}, {\"status\": \"affected\", \"version\": \"2.0(1n)\"}, {\"status\": \"affected\", \"version\": \"2.0(1m)\"}, {\"status\": \"affected\", \"version\": \"2.0(1r)\"}, {\"status\": \"affected\", \"version\": \"2.1(2e)\"}, {\"status\": \"affected\", \"version\": \"4.2(2e)\"}, {\"status\": \"affected\", \"version\": \"4.2(3j)\"}, {\"status\": \"affected\", \"version\": \"4.2(3n)\"}, {\"status\": \"affected\", \"version\": \"2.0(1l)\"}, {\"status\": \"affected\", \"version\": \"2.2(2e)\"}, {\"status\": \"affected\", \"version\": \"2.2(3r)\"}, {\"status\": \"affected\", \"version\": \"3.0(2k)\"}, {\"status\": \"affected\", \"version\": \"2.1(3g)\"}, {\"status\": \"affected\", \"version\": \"4.0(1h)\"}, {\"status\": \"affected\", \"version\": \"2.0(1o)\"}, {\"status\": \"affected\", \"version\": \"2.2(3p)\"}, {\"status\": \"affected\", \"version\": \"1.2(3e)\"}, {\"status\": \"affected\", \"version\": \"2.2(3s)\"}, {\"status\": \"affected\", \"version\": \"2.0(2g)\"}, {\"status\": \"affected\", \"version\": \"4.1(1l)\"}, {\"status\": \"affected\", \"version\": \"3.2(9f)\"}, {\"status\": \"affected\", \"version\": \"4.2(3l)\"}, {\"status\": \"affected\", \"version\": \"4.2(2g)\"}, {\"status\": \"affected\", \"version\": \"1.2(3c)\"}, {\"status\": \"affected\", \"version\": \"3.2(7k)\"}, {\"status\": \"affected\", \"version\": \"1.3(2h)\"}, {\"status\": \"affected\", \"version\": \"3.2(9b)\"}, {\"status\": \"affected\", \"version\": \"1.3(2k)\"}, {\"status\": \"affected\", \"version\": \"3.1(2t)\"}, {\"status\": \"affected\", \"version\": \"1.1(2h)\"}, {\"status\": \"affected\", \"version\": \"3.2(3j)\"}, {\"status\": \"affected\", \"version\": \"2.1(2k)\"}, {\"status\": \"affected\", \"version\": \"2.3(1f)\"}, {\"status\": \"affected\", \"version\": \"1.2(3h)\"}, {\"status\": \"affected\", \"version\": \"3.0(1i)\"}, {\"status\": \"affected\", \"version\": \"4.1(2u)\"}, {\"status\": \"affected\", \"version\": \"4.2(1l)\"}, {\"status\": \"affected\", \"version\": \"4.1(1a)\"}, {\"status\": \"affected\", \"version\": \"4.0(3d)\"}, {\"status\": \"affected\", \"version\": \"1.1(4l)\"}, {\"status\": \"affected\", \"version\": \"2.3(1i)\"}, {\"status\": \"affected\", \"version\": \"3.1(2q)\"}, {\"status\": \"affected\", \"version\": \"3.2(4e)\"}, {\"status\": \"affected\", \"version\": \"4.1(1i)\"}, {\"status\": \"affected\", \"version\": \"3.1(1i)\"}, {\"status\": \"affected\", \"version\": \"2.0(2m)\"}, {\"status\": \"affected\", \"version\": \"3.0(2h)\"}, {\"status\": \"affected\", \"version\": \"2.2(2q)\"}, {\"status\": \"affected\", \"version\": \"2.3(1l)\"}, {\"status\": \"affected\", \"version\": \"1.3(1h)\"}, {\"status\": \"affected\", \"version\": \"3.0(2n)\"}, {\"status\": \"affected\", \"version\": \"3.2(5f)\"}, {\"status\": \"affected\", \"version\": \"1.2(1h)\"}, {\"status\": \"affected\", \"version\": \"3.2(1l)\"}, {\"status\": \"affected\", \"version\": \"4.2(1i)\"}, {\"status\": \"affected\", \"version\": \"4.1(2o)\"}, {\"status\": \"affected\", \"version\": \"1.2(1i)\"}, {\"status\": \"affected\", \"version\": \"1.3(1j)\"}, {\"status\": \"affected\", \"version\": \"2.1(1h)\"}, {\"status\": \"affected\", \"version\": \"2.0(2l)\"}, {\"status\": \"affected\", \"version\": \"2.0(2h)\"}, {\"status\": \"affected\", \"version\": \"1.2(2g)\"}, {\"status\": \"affected\", \"version\": \"3.0(1k)\"}, {\"status\": \"affected\", \"version\": \"4.2(1g)\"}, {\"status\": \"affected\", \"version\": \"2.1(2g)\"}, {\"status\": \"affected\", \"version\": \"2.0(1q)\"}, {\"status\": \"affected\", \"version\": \"1.1(1j)\"}, {\"status\": \"affected\", \"version\": \"4.1(2g)\"}, {\"status\": \"affected\", \"version\": \"1.1(1r)\"}, {\"status\": \"affected\", \"version\": \"4.2(2f)\"}, {\"status\": \"affected\", \"version\": \"3.2(6i)\"}, {\"status\": \"affected\", \"version\": \"1.3(1g)\"}, {\"status\": \"affected\", \"version\": \"1.3(2j)\"}, {\"status\": \"affected\", \"version\": \"1.3(2i)\"}, {\"status\": \"affected\", \"version\": \"2.0(2o)\"}, {\"status\": \"affected\", \"version\": \"2.2(4q)\"}, {\"status\": \"affected\", \"version\": \"2.3(1o)\"}, {\"status\": \"affected\", \"version\": \"3.2(3i)\"}, {\"status\": \"affected\", \"version\": \"2.2(2j)\"}, {\"status\": \"affected\", \"version\": \"1.1(1d)\"}, {\"status\": \"affected\", \"version\": \"2.0(2n)\"}, {\"status\": \"affected\", \"version\": \"2.2(3t)\"}, {\"status\": \"affected\", \"version\": \"3.2(3n)\"}, {\"status\": \"affected\", \"version\": \"1.1(4g)\"}, {\"status\": \"affected\", \"version\": \"4.1(2x)\"}, {\"status\": \"affected\", \"version\": \"3.2(5d)\"}, {\"status\": \"affected\", \"version\": \"3.1(2o)\"}, {\"status\": \"affected\", \"version\": \"1.2(2i)\"}, {\"status\": \"affected\", \"version\": \"2.1(2f)\"}, {\"status\": \"affected\", \"version\": \"1.3(2f)\"}, {\"status\": \"affected\", \"version\": \"4.2(3q)\"}, {\"status\": \"affected\", \"version\": \"4.1(1j)\"}, {\"status\": \"affected\", \"version\": \"2.0(2f)\"}, {\"status\": \"affected\", \"version\": \"2.3(1e)\"}, {\"status\": \"affected\", \"version\": \"1.1(1s)\"}, {\"status\": \"affected\", \"version\": \"3.1(2v)\"}, {\"status\": \"affected\", \"version\": \"4.1(2w)\"}, {\"status\": \"affected\", \"version\": \"1.1(4i)\"}, {\"status\": \"affected\", \"version\": \"3.1(2u)\"}, {\"status\": \"affected\", \"version\": \"1.1(4f)\"}, {\"status\": \"affected\", \"version\": \"3.0(2m)\"}, {\"status\": \"affected\", \"version\": \"2.0(1k)\"}, {\"status\": \"affected\", \"version\": \"3.2(2o)\"}, {\"status\": \"affected\", \"version\": \"3.2(3r)\"}, {\"status\": \"affected\", \"version\": \"1.1(2i)\"}, {\"status\": \"affected\", \"version\": \"4.0(2c)\"}, {\"status\": \"affected\", \"version\": \"1.3(1i)\"}, {\"status\": \"affected\", \"version\": \"4.1(2s)\"}, {\"status\": \"affected\", \"version\": \"3.2(7f)\"}, {\"status\": \"affected\", \"version\": \"1.2(3m)\"}, {\"status\": \"affected\", \"version\": \"3.2(3o)\"}, {\"status\": \"affected\", \"version\": \"3.1(2s)\"}, {\"status\": \"affected\", \"version\": \"3.2(2l)\"}, {\"status\": \"affected\", \"version\": \"4.2(1j)\"}, {\"status\": \"affected\", \"version\": \"2.3(1p)\"}, {\"status\": \"affected\", \"version\": \"2.1(4a)\"}, {\"status\": \"affected\", \"version\": \"1.1(1n)\"}, {\"status\": \"affected\", \"version\": \"2.2(1n)\"}, {\"status\": \"affected\", \"version\": \"2.2(4p)\"}, {\"status\": \"affected\", \"version\": \"2.1(3j)\"}, {\"status\": \"affected\", \"version\": \"4.2(4i)\"}, {\"status\": \"affected\", \"version\": \"3.2(9h)\"}, {\"status\": \"affected\", \"version\": \"5.0(1k)\"}, {\"status\": \"affected\", \"version\": \"4.2(4k)\"}, {\"status\": \"affected\", \"version\": \"5.0(1l)\"}, {\"status\": \"affected\", \"version\": \"5.0(2e)\"}, {\"status\": \"affected\", \"version\": \"4.2(4o)\"}, {\"status\": \"affected\", \"version\": \"4.2(4p)\"}, {\"status\": \"affected\", \"version\": \"5.0(2h)\"}, {\"status\": \"affected\", \"version\": \"4.2(5k)\"}, {\"status\": \"affected\", \"version\": \"4.2(5l)\"}, {\"status\": \"affected\", \"version\": \"4.2(5n)\"}, {\"status\": \"affected\", \"version\": \"5.1(1h)\"}, {\"status\": \"affected\", \"version\": \"4.2(6d)\"}, {\"status\": \"affected\", \"version\": \"5.1(2e)\"}, {\"status\": \"affected\", \"version\": \"4.2(6g)\"}, {\"status\": \"affected\", \"version\": \"4.2(6h)\"}, {\"status\": \"affected\", \"version\": \"5.1(3e)\"}, {\"status\": \"affected\", \"version\": \"3.2(10e)\"}, {\"status\": \"affected\", \"version\": \"4.2(6l)\"}, {\"status\": \"affected\", \"version\": \"4.2(7f)\"}, {\"status\": \"affected\", \"version\": \"5.1(4c)\"}, {\"status\": \"affected\", \"version\": \"4.2(6o)\"}, {\"status\": \"affected\", \"version\": \"5.2(1g)\"}, {\"status\": \"affected\", \"version\": \"5.2(2e)\"}, {\"status\": \"affected\", \"version\": \"4.2(7l)\"}, {\"status\": \"affected\", \"version\": \"3.2(10f)\"}, {\"status\": \"affected\", \"version\": \"5.2(2f)\"}, {\"status\": \"affected\", \"version\": \"5.2(2g)\"}, {\"status\": \"affected\", \"version\": \"4.2(7q)\"}, {\"status\": \"affected\", \"version\": \"5.2(2h)\"}, {\"status\": \"affected\", \"version\": \"5.2(3f)\"}, {\"status\": \"affected\", \"version\": \"5.2(3e)\"}, {\"status\": \"affected\", \"version\": \"5.2(3g)\"}, {\"status\": \"affected\", \"version\": \"4.2(7r)\"}, {\"status\": \"affected\", \"version\": \"4.2(7s)\"}, {\"status\": \"affected\", \"version\": \"5.2(4d)\"}, {\"status\": \"affected\", \"version\": \"5.2(4e)\"}, {\"status\": \"affected\", \"version\": \"4.2(7t)\"}, {\"status\": \"affected\", \"version\": \"5.2(5d)\"}, {\"status\": \"affected\", \"version\": \"3.2(10g)\"}, {\"status\": \"affected\", \"version\": \"5.2(5c)\"}, {\"status\": \"affected\", \"version\": \"6.0(1g)\"}, {\"status\": \"affected\", \"version\": \"4.2(7u)\"}, {\"status\": \"affected\", \"version\": \"5.2(5e)\"}, {\"status\": \"affected\", \"version\": \"5.2(4f)\"}, {\"status\": \"affected\", \"version\": \"5.2(6e)\"}, {\"status\": \"affected\", \"version\": \"6.0(1j)\"}, {\"status\": \"affected\", \"version\": \"5.2(6g)\"}, {\"status\": \"affected\", \"version\": \"5.2(7f)\"}, {\"status\": \"affected\", \"version\": \"4.2(7v)\"}, {\"status\": \"affected\", \"version\": \"5.2(7g)\"}, {\"status\": \"affected\", \"version\": \"6.0(2h)\"}, {\"status\": \"affected\", \"version\": \"4.2(7w)\"}, {\"status\": \"affected\", \"version\": \"5.2(6h)\"}, {\"status\": \"affected\", \"version\": \"5.2(4h)\"}, {\"status\": \"affected\", \"version\": \"5.2(8d)\"}, {\"status\": \"affected\", \"version\": \"6.0(2j)\"}, {\"status\": \"affected\", \"version\": \"5.2(8e)\"}, {\"status\": \"affected\", \"version\": \"6.0(3d)\"}, {\"status\": \"affected\", \"version\": \"6.0(3e)\"}, {\"status\": \"affected\", \"version\": \"5.2(8f)\"}, {\"status\": \"affected\", \"version\": \"5.2(8g)\"}, {\"status\": \"affected\", \"version\": \"5.3(1d)\"}, {\"status\": \"affected\", \"version\": \"5.2(8h)\"}, {\"status\": \"affected\", \"version\": \"6.0(4c)\"}, {\"status\": \"affected\", \"version\": \"5.3(2a)\"}, {\"status\": \"affected\", \"version\": \"5.2(8i)\"}, {\"status\": \"affected\", \"version\": \"6.0(5h)\"}, {\"status\": \"affected\", \"version\": \"5.3(2b)\"}, {\"status\": \"affected\", \"version\": \"6.0(3g)\"}, {\"status\": \"affected\", \"version\": \"6.0(5j)\"}], \"defaultStatus\": \"unknown\"}], \"exploits\": [{\"lang\": \"en\", \"value\": \"The Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory.\"}], \"references\": [{\"url\": \"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apic-cousmo-uBpBYGbq\", \"name\": \"cisco-sa-apic-cousmo-uBpBYGbq\"}], \"descriptions\": [{\"lang\": \"en\", \"value\": \"A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to modify the behavior of default system policies, such as quality of service (QoS) policies, on an affected system.\u0026nbsp;This vulnerability is due to improper access control when restricted security domains are used to implement multi-tenancy. An attacker with a valid user account associated with a restricted security domain could exploit this vulnerability. A successful exploit could allow the attacker to read, modify, or delete child policies created under default system policies, which are implicitly used by all tenants in the fabric, resulting in disruption of network traffic. Exploitation is not possible for policies under tenants that an attacker has no authorization to access.\"}], \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"type\": \"cwe\", \"cweId\": \"CWE-284\", \"description\": \"Improper Access Control\"}]}], \"providerMetadata\": {\"orgId\": \"d1c1063e-7a18-46af-9102-31f8928bc633\", \"shortName\": \"cisco\", \"dateUpdated\": \"2024-08-28T16:19:08.343Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2024-20279\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2024-08-28T17:54:51.419Z\", \"dateReserved\": \"2023-11-08T15:08:07.625Z\", \"assignerOrgId\": \"d1c1063e-7a18-46af-9102-31f8928bc633\", \"datePublished\": \"2024-08-28T16:19:08.343Z\", \"assignerShortName\": \"cisco\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…