Skip to main content

Cisco APIC Vulnerabilities Patched

Cisco has released three patches for vulnerabilities found in Cisco Application Policy Infrastructure Controller and Cisco Virtual Network Function Element Manager:
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

Cisco has released three patches for vulnerabilities found in Cisco Application Policy Infrastructure Controller and Cisco Virtual Network Function Element Manager:

Threat details

  • CVE-2017-6767 - Cisco Application Policy Infrastructure Controller SSH Privilege Escalation Vulnerability
  • CVE-2017-6768 - Cisco Application Policy Infrastructure Controller Custom Binary Privilege Escalation Vulnerability
  • CVE-2017-6710 - Cisco Virtual Network Function Element Manager Arbitrary Command Execution Vulnerability

Remediation steps

Type Step
  • Patch the above affected products to the most recent versions.
  • Ensure that accounts issued are given to authorised personnel only.
  • Ensure all unnecessary accounts are deleted/blocked.
  • Ensure that strong password and account policies are enforced for all accounts that have access to management interfaces over SSH.


Last edited: 17 February 2020 11:28 am