CVE-2016-6457: Cisco Application Policy Infrastructure Controller

Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.

A vulnerability in the Cisco Nexus 9000 Series Platform Leaf Switches for Application Centric Infrastructure (ACI) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability affects Cisco Nexus 9000 Series Leaf Switches (TOR) - ACI Mode and Cisco Application Policy Infrastructure Controller (APIC). More Information: CSCuy93241. Known Affected Releases: 11.2(2x) 11.2(3x) 11.3(1x) 11.3(2x) 12.0(1x). Known Fixed Releases: 11.2(2i) 11.2(2j) 11.2(3f) 11.2(3g) 11.2(3h) 11.2(3l) 11.3(0.236) 11.3(1j) 11.3(2i) 11.3(2j) 12.0(1r).

Affected products

  • Cisco Application Policy Infrastructure Controller: version 1.2(2) only; version 1.2(3) only; version 1.3(1) only; version 1.3(2) only; version 2.0(1) only
  • Cisco NX-OS: version 11.2(2g) only; version 11.2(2h) only; version 11.2(2i) only; version 11.2(3c) only; version 11.2(3e) only; version 11.2(3h) only; …

Published 2016-11-19. Last modified 2026-06-17.