Database/Control plane, storage & DevOps
Cisco ACI Multi-Site Orchestrator (Application Services Engine): Complete unauthenticated authentication bypass on the
Impact
Complete unauthenticated authentication bypass on the controller that programs policy across every ACI site. Whoever gets this owns the tenant separation model for the entire multi-site fabric — they can write EPG and contract policy that stitches any tenant to any other. It is a 10.0 for a reason.
Who can reach it
Unauthenticated, remote — anything that can reach the MSO API endpoint. If the orchestrator's management interface is on a flat ops network, that is a very large set of machines.
What to do
Upgrade the MSO application. Application-level upgrade rather than a switch reload, so the data plane stays up — but treat any pre-patch exposure as a policy compromise and re-audit every contract and EPG binding afterwards, which is the real cost.
References
Related entries
- GitLab: Image files passed unvalidated to a file parser (ExifTool)CVE-2021-22205 · GitLabCritical
- Eaton Intelligent Power Manager (IPM) prior to 1.69: Unauthenticated remote code execution on Eaton's power-managementCVE-2021-23281 · Eaton Intelligent Power Manager (IPM) prior to 1.69Critical
- Redis: Debian/Ubuntu packaging leaves a Lua sandbox escapeCVE-2022-0543 · RedisCritical
- Software House iSTAR Ultra door controller (before 6.8.9.CU01): Unauthenticated command injection giving rootCVE-2022-21941 · Software House iSTAR Ultra door controller (before 6.8.9.CU01)Critical
- HID Mercury intelligent controllers sold by Carrier LenelS2 (LNL-X2210/X2220/X3300/X4420/4420CVE-2022-31481 · HID Mercury intelligent controllers sold by Carrier LenelS2Critical
- GitLab: Unauthenticated path traversal reads arbitrary server files when an attachment sits under 5+ nested groupsCVE-2023-2825 · GitLabCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.