12-08-2021 11:56 PM
Hi folks,
Recenly got a pentest team coming in with a few nginx vulnerabilities found on Cisco APIC.
I would like to ask:
For point 2, since there are no such mapping documents, I cannot ensure if upgrading the APIC is the best way to go.
12-09-2021 01:13 AM - edited 12-09-2021 01:13 AM
Can you share the CVEs and the running version you have?
You might search them on Bug Search Tool and see if there are any related bugs linked to them. You will see there if any upgrades will resolve the problem.
Cheers,
Sergiu
12-09-2021 07:03 PM
Hi Sergiu,
The running code is 4.2(4i). CVE ID is CVE-2021-23017. I managed to find a result on Bug Search Tool but it doesn't show mitigation steps directly on APIC.
12-10-2021 10:52 AM
Last I checked we were using nginx 1.17.3 on ACI. I've opened a discussion with Engineering to see if/when our next update for this service is scheduled. This would require a software upgrade/patch but I'm looking into this.
Stay tuned.
Robert
12-12-2021 07:01 AM
Thanks Robert for the info.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide