CVE-2016-1420: High severity cisco application policy infrastructure controller vulnerability
The installation component on Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.3(2f) mishandles binary files, which allows local users to obtain root access via unspecified vectors, aka Bug ID CSCuz72347.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1420?
CVE-2016-1420 has a critical severity rating due to its potential for local users to gain root access.
How do I fix CVE-2016-1420?
To fix CVE-2016-1420, upgrade the Cisco Application Policy Infrastructure Controller software to version 1.3(2f) or later.
Which devices are affected by CVE-2016-1420?
CVE-2016-1420 affects Cisco Application Policy Infrastructure Controller devices with software versions prior to 1.3(2f).
What type of access does CVE-2016-1420 provide to attackers?
CVE-2016-1420 allows local users to obtain root access on affected Cisco Application Policy Infrastructure Controller devices.
When was CVE-2016-1420 disclosed?
CVE-2016-1420 was disclosed on June 9, 2016.