Cisco ACI Multi-Site Orchestrator Application Services Engine Deployment Authentication Bypass (cisco-sa-mso-authbyp-bb5GmBQv)

critical Nessus Plugin ID 151020

Synopsis

The remote device is missing a vendor-supplied security patch

Description

According to its self-reported version, a vulnerability in an API endpoint of Cisco ACI Multi-Site Orchestrator (MSO) installed on the Application Services Engine could allow an unauthenticated, remote attacker to bypass authentication on an affected device. The vulnerability is due to improper token validation on a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted request to the affected API. A successful exploit could allow the attacker to receive a token with administrator-level privileges that could be used to authenticate to the API on affected MSO and managed Cisco Application Policy Infrastructure Controller (APIC) devices.

Please see the included Cisco BIDs and Cisco Security Advisory for more information.

Solution

Upgrade to the relevant fixed version referenced in Cisco bug ID CSCvw14141

See Also

http://www.nessus.org/u?af0345e0

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvw14141

Plugin Details

Severity: Critical

ID: 151020

File Name: cisco-sa-mso-authbyp-bb5GmBQv.nasl

Version: 1.3

Type: remote

Family: CISCO

Published: 6/28/2021

Updated: 6/29/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.5

CVSS v2

Risk Factor: High

Base Score: 9.3

Temporal Score: 6.9

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2021-1388

CVSS v3

Risk Factor: Critical

Base Score: 10

Temporal Score: 8.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: x-cpe:/a:cisco:aci_multisite_orchestrator

Required KB Items: installed_sw/Cisco ACI Multi-Site Orchestrator

Exploit Ease: No known exploits are available

Patch Publication Date: 2/24/2021

Vulnerability Publication Date: 2/24/2021

Reference Information

CVE: CVE-2021-1388

CWE: 269

CISCO-SA: cisco-sa-mso-authbyp-bb5GmBQv

CISCO-BUG-ID: CSCvw14141