CVE-2024-20478

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
28/08/2024
Last modified:
01/08/2025

Description

A vulnerability in the software upgrade component of Cisco Application Policy Infrastructure Controller (APIC) and Cisco&amp;nbsp;Cloud Network Controller, formerly Cisco Cloud APIC, could allow an authenticated, remote attacker with Administrator-level privileges to install a modified software image, leading to arbitrary code injection on an affected system.<br /> <br /> This vulnerability is due to insufficient signature validation of software images. An attacker could exploit this vulnerability by installing a modified software image. A successful exploit could allow the attacker to execute arbitrary code on the affected system and elevate their privileges to root.<br /> Note: Administrators should always validate the hash of any upgrade image before uploading it to Cisco APIC and Cisco Cloud Network Controller.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.1\(1d\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.1\(1j\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.1\(1n\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.1\(1o\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.1\(1r\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.1\(1s\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.1\(2h\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.1\(2i\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.1\(3f\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.1\(4e\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.1\(4f\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.1\(4g\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.1\(4i\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.1\(4l\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.1\(4m\):*:*:*:*:*:*:*