CVE-2021-1396: Cisco Application Services Engine Unauthorized Access Vulnerabilities
Multiple vulnerabilities in Cisco Application Services Engine could allow an unauthenticated, remote attacker to gain privileged access to host-level operations or to learn device-specific information, create diagnostic files, and make limited configuration changes. For more information about these vulnerabilities, see the Details section of this advisory.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-1396?
CVE-2021-1396 is a vulnerability in Cisco Application Services Engine that could allow an unauthenticated remote attacker to gain privileged access to host-level operations or to learn device-specific information.
How severe is CVE-2021-1396?
CVE-2021-1396 has a severity score of 6.5, which is considered critical.
Which software is affected by CVE-2021-1396?
The Cisco Application Services Engine versions 1.1 up to and including 1.1(3e) and Cisco Application Policy Infrastructure Controller version 1.1.3-c and 1.1.3-d are affected by CVE-2021-1396.
How can an attacker exploit CVE-2021-1396?
An unauthenticated remote attacker can exploit CVE-2021-1396 to gain privileged access to host-level operations or to learn device-specific information, create diagnostic files, and make limited configuration changes.
Where can I find more information about CVE-2021-1396?
You can find more information about CVE-2021-1396 in the Cisco Security Advisory: [Cisco Security Advisory](https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-case-mvuln-dYrDPC6w).