First published: Fri Oct 16 2015(Updated: )
Cisco Application Policy Infrastructure Controller (APIC) 1.1j allows local users to gain privileges via vectors involving addition of an SSH key, aka Bug ID CSCuw46076.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Application Policy Infrastructure Controller (APIC) | =1.1\(1j\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6333 has a moderate severity rating that allows local users to gain unauthorized privileges.
To mitigate CVE-2015-6333, ensure that unauthorized SSH keys are not added by local users and regularly review user permissions.
CVE-2015-6333 affects users of Cisco Application Policy Infrastructure Controller (APIC) version 1.1j.
CVE-2015-6333 can lead to unauthorized access, allowing local users to escalate their privileges within the system.
While there is no official workaround for CVE-2015-6333, restricting physical access and monitoring user accounts can help mitigate the risk.