CVE-2016-6413: Cisco Application Policy Infrastructure Controller

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

The installation procedure on Cisco Application Policy Infrastructure Controller (APIC) devices 1.3(2f) mishandles binary files, which allows local users to obtain root access via unspecified vectors, aka Bug ID CSCva50496.

Affected products

  • Cisco Application Policy Infrastructure Controller: version 1.3(2f) only

Published 2016-09-24. Last modified 2026-06-17.