CVE-2024-20478

A vulnerability in the software upgrade component of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Network Controller, formerly Cisco Cloud APIC, could allow an authenticated, remote attacker with Administrator-level privileges to install a modified software image, leading to arbitrary code injection on an affected system.

This vulnerability is due to insufficient signature validation of software images. An attacker could exploit this vulnerability by installing a modified software image. A successful exploit could allow the attacker to execute arbitrary code on the affected system and elevate their privileges to root.
Note: Administrators should always validate the hash of any upgrade image before uploading it to Cisco APIC and Cisco Cloud Network Controller.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
ciscoCNA
6.5 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 28%
VendorProductVersion
ciscoapplication_policy_infrastructure_controller
1.1\(1d\)
ciscoapplication_policy_infrastructure_controller
1.1\(1j\)
ciscoapplication_policy_infrastructure_controller
1.1\(1n\)
ciscoapplication_policy_infrastructure_controller
1.1\(1o\)
ciscoapplication_policy_infrastructure_controller
1.1\(1r\)
ciscoapplication_policy_infrastructure_controller
1.1\(1s\)
ciscoapplication_policy_infrastructure_controller
1.1\(2h\)
ciscoapplication_policy_infrastructure_controller
1.1\(2i\)
ciscoapplication_policy_infrastructure_controller
1.1\(3f\)
ciscoapplication_policy_infrastructure_controller
1.1\(4e\)
ciscoapplication_policy_infrastructure_controller
1.1\(4f\)
ciscoapplication_policy_infrastructure_controller
1.1\(4g\)
ciscoapplication_policy_infrastructure_controller
1.1\(4i\)
ciscoapplication_policy_infrastructure_controller
1.1\(4l\)
ciscoapplication_policy_infrastructure_controller
1.1\(4m\)
ciscoapplication_policy_infrastructure_controller
1.2\(1h\)
ciscoapplication_policy_infrastructure_controller
1.2\(1i\)
ciscoapplication_policy_infrastructure_controller
1.2\(1k\)
ciscoapplication_policy_infrastructure_controller
1.2\(1m\)
ciscoapplication_policy_infrastructure_controller
1.2\(2g\)
ciscoapplication_policy_infrastructure_controller
1.2\(2h\)
ciscoapplication_policy_infrastructure_controller
1.2\(2i\)
ciscoapplication_policy_infrastructure_controller
1.2\(2j\)
ciscoapplication_policy_infrastructure_controller
1.2\(3c\)
ciscoapplication_policy_infrastructure_controller
1.2\(3e\)
ciscoapplication_policy_infrastructure_controller
1.2\(3h\)
ciscoapplication_policy_infrastructure_controller
1.2\(3m\)
ciscoapplication_policy_infrastructure_controller
1.3\(1g\)
ciscoapplication_policy_infrastructure_controller
1.3\(1h\)
ciscoapplication_policy_infrastructure_controller
1.3\(1i\)
ciscoapplication_policy_infrastructure_controller
1.3\(1j\)
ciscoapplication_policy_infrastructure_controller
1.3\(2f\)
ciscoapplication_policy_infrastructure_controller
1.3\(2h\)
ciscoapplication_policy_infrastructure_controller
1.3\(2i\)
ciscoapplication_policy_infrastructure_controller
1.3\(2j\)
ciscoapplication_policy_infrastructure_controller
1.3\(2k\)
ciscoapplication_policy_infrastructure_controller
2.0\(1k\)
ciscoapplication_policy_infrastructure_controller
2.0\(1l\)
ciscoapplication_policy_infrastructure_controller
2.0\(1m\)
ciscoapplication_policy_infrastructure_controller
2.0\(1n\)
ciscoapplication_policy_infrastructure_controller
2.0\(1o\)
ciscoapplication_policy_infrastructure_controller
2.0\(1p\)
ciscoapplication_policy_infrastructure_controller
2.0\(1q\)
ciscoapplication_policy_infrastructure_controller
2.0\(1r\)
ciscoapplication_policy_infrastructure_controller
2.0\(2f\)
ciscoapplication_policy_infrastructure_controller
2.0\(2g\)
ciscoapplication_policy_infrastructure_controller
2.0\(2h\)
ciscoapplication_policy_infrastructure_controller
2.0\(2l\)
ciscoapplication_policy_infrastructure_controller
2.0\(2m\)
ciscoapplication_policy_infrastructure_controller
2.0\(2n\)
ciscoapplication_policy_infrastructure_controller
2.0\(2o\)
ciscoapplication_policy_infrastructure_controller
2.1\(1h\)
ciscoapplication_policy_infrastructure_controller
2.1\(1i\)
ciscoapplication_policy_infrastructure_controller
2.1\(2e\)
ciscoapplication_policy_infrastructure_controller
2.1\(2f\)
ciscoapplication_policy_infrastructure_controller
2.1\(2g\)
ciscoapplication_policy_infrastructure_controller
2.1\(2k\)
ciscoapplication_policy_infrastructure_controller
2.1\(3g\)
ciscoapplication_policy_infrastructure_controller
2.1\(3h\)
ciscoapplication_policy_infrastructure_controller
2.1\(3j\)
ciscoapplication_policy_infrastructure_controller
2.1\(4a\)
ciscoapplication_policy_infrastructure_controller
2.2\(1k\)
ciscoapplication_policy_infrastructure_controller
2.2\(1n\)
ciscoapplication_policy_infrastructure_controller
2.2\(1o\)
ciscoapplication_policy_infrastructure_controller
2.2\(2e\)
ciscoapplication_policy_infrastructure_controller
2.2\(2f\)
ciscoapplication_policy_infrastructure_controller
2.2\(2i\)
ciscoapplication_policy_infrastructure_controller
2.2\(2j\)
ciscoapplication_policy_infrastructure_controller
2.2\(2k\)
ciscoapplication_policy_infrastructure_controller
2.2\(2q\)
ciscoapplication_policy_infrastructure_controller
2.2\(3j\)
ciscoapplication_policy_infrastructure_controller
2.2\(3p\)
ciscoapplication_policy_infrastructure_controller
2.2\(3r\)
ciscoapplication_policy_infrastructure_controller
2.2\(3s\)
ciscoapplication_policy_infrastructure_controller
2.2\(3t\)
ciscoapplication_policy_infrastructure_controller
2.2\(4f\)
ciscoapplication_policy_infrastructure_controller
2.2\(4p\)
ciscoapplication_policy_infrastructure_controller
2.2\(4q\)
ciscoapplication_policy_infrastructure_controller
2.2\(4r\)
ciscoapplication_policy_infrastructure_controller
2.3\(1e\)
ciscoapplication_policy_infrastructure_controller
2.3\(1f\)
ciscoapplication_policy_infrastructure_controller
2.3\(1i\)
ciscoapplication_policy_infrastructure_controller
2.3\(1l\)
ciscoapplication_policy_infrastructure_controller
2.3\(1o\)
ciscoapplication_policy_infrastructure_controller
2.3\(1p\)
ciscoapplication_policy_infrastructure_controller
3.0\(1i\)
ciscoapplication_policy_infrastructure_controller
3.0\(1k\)
ciscoapplication_policy_infrastructure_controller
3.0\(2h\)
ciscoapplication_policy_infrastructure_controller
3.0\(2k\)
ciscoapplication_policy_infrastructure_controller
3.0\(2m\)
ciscoapplication_policy_infrastructure_controller
3.0\(2n\)
ciscoapplication_policy_infrastructure_controller
3.1\(1i\)
ciscoapplication_policy_infrastructure_controller
3.1\(2m\)
ciscoapplication_policy_infrastructure_controller
3.1\(2o\)
ciscoapplication_policy_infrastructure_controller
3.1\(2p\)
ciscoapplication_policy_infrastructure_controller
3.1\(2q\)
ciscoapplication_policy_infrastructure_controller
3.1\(2s\)
ciscoapplication_policy_infrastructure_controller
3.1\(2t\)
ciscoapplication_policy_infrastructure_controller
3.1\(2u\)
ciscoapplication_policy_infrastructure_controller
3.1\(2v\)
ciscoapplication_policy_infrastructure_controller
3.2\(1l\)
ciscoapplication_policy_infrastructure_controller
3.2\(1m\)
ciscoapplication_policy_infrastructure_controller
3.2\(2l\)
ciscoapplication_policy_infrastructure_controller
3.2\(2o\)
ciscoapplication_policy_infrastructure_controller
3.2\(3i\)
ciscoapplication_policy_infrastructure_controller
3.2\(3j\)
ciscoapplication_policy_infrastructure_controller
3.2\(3n\)
ciscoapplication_policy_infrastructure_controller
3.2\(3o\)
ciscoapplication_policy_infrastructure_controller
3.2\(3r\)
ciscoapplication_policy_infrastructure_controller
3.2\(3s\)
ciscoapplication_policy_infrastructure_controller
3.2\(4d\)
ciscoapplication_policy_infrastructure_controller
3.2\(4e\)
ciscoapplication_policy_infrastructure_controller
3.2\(5d\)
ciscoapplication_policy_infrastructure_controller
3.2\(5e\)
ciscoapplication_policy_infrastructure_controller
3.2\(5f\)
ciscoapplication_policy_infrastructure_controller
3.2\(6i\)
ciscoapplication_policy_infrastructure_controller
3.2\(7f\)
ciscoapplication_policy_infrastructure_controller
3.2\(7k\)
ciscoapplication_policy_infrastructure_controller
3.2\(8d\)
ciscoapplication_policy_infrastructure_controller
3.2\(9b\)
ciscoapplication_policy_infrastructure_controller
3.2\(9f\)
ciscoapplication_policy_infrastructure_controller
3.2\(9h\)
ciscoapplication_policy_infrastructure_controller
3.2\(10e\)
ciscoapplication_policy_infrastructure_controller
3.2\(10f\)
ciscoapplication_policy_infrastructure_controller
3.2\(10g\)
ciscoapplication_policy_infrastructure_controller
3.2\(41d\)
ciscoapplication_policy_infrastructure_controller
4.0\(1h\)
ciscoapplication_policy_infrastructure_controller
4.0\(2c\)
ciscoapplication_policy_infrastructure_controller
4.0\(3c\)
ciscoapplication_policy_infrastructure_controller
4.0\(3d\)
ciscoapplication_policy_infrastructure_controller
4.1\(1a\)
ciscoapplication_policy_infrastructure_controller
4.1\(1i\)
ciscoapplication_policy_infrastructure_controller
4.1\(1j\)
ciscoapplication_policy_infrastructure_controller
4.1\(1k\)
ciscoapplication_policy_infrastructure_controller
4.1\(1l\)
ciscoapplication_policy_infrastructure_controller
4.1\(2g\)
ciscoapplication_policy_infrastructure_controller
4.1\(2m\)
ciscoapplication_policy_infrastructure_controller
4.1\(2o\)
ciscoapplication_policy_infrastructure_controller
4.1\(2s\)
ciscoapplication_policy_infrastructure_controller
4.1\(2u\)
ciscoapplication_policy_infrastructure_controller
4.1\(2w\)
ciscoapplication_policy_infrastructure_controller
4.1\(2x\)
ciscoapplication_policy_infrastructure_controller
4.2\(1g\)
ciscoapplication_policy_infrastructure_controller
4.2\(1i\)
ciscoapplication_policy_infrastructure_controller
4.2\(1j\)
ciscoapplication_policy_infrastructure_controller
4.2\(1l\)
ciscoapplication_policy_infrastructure_controller
4.2\(2e\)
ciscoapplication_policy_infrastructure_controller
4.2\(2f\)
ciscoapplication_policy_infrastructure_controller
4.2\(2g\)
ciscoapplication_policy_infrastructure_controller
4.2\(3j\)
ciscoapplication_policy_infrastructure_controller
4.2\(3l\)
ciscoapplication_policy_infrastructure_controller
4.2\(3n\)
ciscoapplication_policy_infrastructure_controller
4.2\(3q\)
ciscoapplication_policy_infrastructure_controller
4.2\(4i\)
ciscoapplication_policy_infrastructure_controller
4.2\(4k\)
ciscoapplication_policy_infrastructure_controller
4.2\(4o\)
ciscoapplication_policy_infrastructure_controller
4.2\(4p\)
ciscoapplication_policy_infrastructure_controller
4.2\(5k\)
ciscoapplication_policy_infrastructure_controller
4.2\(5l\)
ciscoapplication_policy_infrastructure_controller
4.2\(5n\)
ciscoapplication_policy_infrastructure_controller
4.2\(6d\)
ciscoapplication_policy_infrastructure_controller
4.2\(6g\)
ciscoapplication_policy_infrastructure_controller
4.2\(6h\)
ciscoapplication_policy_infrastructure_controller
4.2\(6l\)
ciscoapplication_policy_infrastructure_controller
4.2\(6o\)
ciscoapplication_policy_infrastructure_controller
4.2\(7f\)
ciscoapplication_policy_infrastructure_controller
4.2\(7l\)
ciscoapplication_policy_infrastructure_controller
4.2\(7q\)
ciscoapplication_policy_infrastructure_controller
4.2\(7r\)
ciscoapplication_policy_infrastructure_controller
4.2\(7s\)
ciscoapplication_policy_infrastructure_controller
4.2\(7t\)
ciscoapplication_policy_infrastructure_controller
4.2\(7u\)
ciscoapplication_policy_infrastructure_controller
4.2\(7v\)
ciscoapplication_policy_infrastructure_controller
4.2\(7w\)
ciscoapplication_policy_infrastructure_controller
5.0\(1k\)
ciscoapplication_policy_infrastructure_controller
5.0\(1l\)
ciscoapplication_policy_infrastructure_controller
5.0\(2e\)
ciscoapplication_policy_infrastructure_controller
5.0\(2h\)
ciscoapplication_policy_infrastructure_controller
5.1\(1h\)
ciscoapplication_policy_infrastructure_controller
5.1\(2e\)
ciscoapplication_policy_infrastructure_controller
5.1\(3e\)
ciscoapplication_policy_infrastructure_controller
5.1\(4c\)
ciscoapplication_policy_infrastructure_controller
5.2\(1g\)
ciscoapplication_policy_infrastructure_controller
5.2\(2e\)
ciscoapplication_policy_infrastructure_controller
5.2\(2f\)
ciscoapplication_policy_infrastructure_controller
5.2\(2g\)
ciscoapplication_policy_infrastructure_controller
5.2\(2h\)
ciscoapplication_policy_infrastructure_controller
5.2\(3e\)
ciscoapplication_policy_infrastructure_controller
5.2\(3f\)
ciscoapplication_policy_infrastructure_controller
5.2\(3g\)
ciscoapplication_policy_infrastructure_controller
5.2\(4d\)
ciscoapplication_policy_infrastructure_controller
5.2\(4e\)
ciscoapplication_policy_infrastructure_controller
5.2\(4f\)
ciscoapplication_policy_infrastructure_controller
5.2\(4h\)
ciscoapplication_policy_infrastructure_controller
5.2\(5c\)
ciscoapplication_policy_infrastructure_controller
5.2\(5d\)
ciscoapplication_policy_infrastructure_controller
5.2\(5e\)
ciscoapplication_policy_infrastructure_controller
5.2\(6e\)
ciscoapplication_policy_infrastructure_controller
5.2\(6g\)
ciscoapplication_policy_infrastructure_controller
5.2\(6h\)
ciscoapplication_policy_infrastructure_controller
5.2\(7f\)
ciscoapplication_policy_infrastructure_controller
5.2\(7g\)
ciscoapplication_policy_infrastructure_controller
5.2\(8d\)
ciscoapplication_policy_infrastructure_controller
5.2\(8e\)
ciscoapplication_policy_infrastructure_controller
5.2\(8f\)
ciscoapplication_policy_infrastructure_controller
5.2\(8g\)
ciscoapplication_policy_infrastructure_controller
5.2\(8h\)
ciscoapplication_policy_infrastructure_controller
5.2\(8i\)
ciscoapplication_policy_infrastructure_controller
5.3\(1d\)
ciscoapplication_policy_infrastructure_controller
5.3\(2a\)
ciscoapplication_policy_infrastructure_controller
5.3\(2b\)
ciscoapplication_policy_infrastructure_controller
5.3\(2c\)
ciscoapplication_policy_infrastructure_controller
6.0\(1g\)
ciscoapplication_policy_infrastructure_controller
6.0\(1j\)
ciscoapplication_policy_infrastructure_controller
6.0\(2h\)
ciscoapplication_policy_infrastructure_controller
6.0\(2j\)
ciscoapplication_policy_infrastructure_controller
6.0\(3d\)
ciscoapplication_policy_infrastructure_controller
6.0\(3e\)
ciscoapplication_policy_infrastructure_controller
6.0\(3g\)
ciscoapplication_policy_infrastructure_controller
6.0\(4c\)
ciscoapplication_policy_infrastructure_controller
6.0\(5h\)
ciscoapplication_policy_infrastructure_controller
6.0\(5j\)
𝑥
= Vulnerable software versions