Cisco Application Policy Infrastructure Controller Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in the Object Model CLI component of Cisco Application Policy Infrastructure Controller (APIC). This issue allows an authenticated, local attacker with CLI access to cause the device to reload unexpectedly, leading to a DoS condition. The vulnerability arises from insufficient input validation, enabling attackers to issue crafted commands that trigger the device reload.

Impact

Exploitation of this vulnerability causes the device to reload, creating a denial-of-service condition.

Remediation

Cisco has released software updates to address this vulnerability. Users should upgrade to version 6.1(4h) if they are on the 6.1 release. For those on releases 6.0 and earlier or 6.2, this vulnerability is not applicable.

Added: Feb 25, 2026, 11:14 PM
Updated: Feb 25, 2026, 11:14 PM

Vulnerability Rating

Custom Algorithm
spread
1.4
impact
2.5
exploitability
3.5
remediation
7.7
relevance
3.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.