CVE-2016-1386: Cisco Application Policy Infrastructure Controller Enterprise Module

High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.

The API in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.0(1) allows remote attackers to spoof administrative notifications via crafted attribute-value pairs, aka Bug ID CSCux15521.

Affected products

  • Cisco Application Policy Infrastructure Controller Enterprise Module: version 1.0.(1) only

Published 2016-04-28. Last modified 2026-06-17.