CVE-2016-1365: Cisco Application Policy Infrastructure Controller Enterprise Module
High severity, CVSS 8.8. EPSS: 2.7% chance of exploitation in the next 30 days.
The Grapevine update process in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.0 allows remote authenticated users to execute arbitrary commands as root via a crafted upgrade parameter, aka Bug ID CSCux15507.
Affected products
- Cisco Application Policy Infrastructure Controller Enterprise Module: version 1.0.10 only
Published 2016-08-18. Last modified 2026-06-17.