{
  "document" : {
    "aggregate_severity" : {
      "text" : "hoch"
    },
    "category" : "csaf_base",
    "csaf_version" : "2.0",
    "distribution" : {
      "tlp" : {
        "label" : "WHITE",
        "url" : "https://www.first.org/tlp/"
      }
    },
    "lang" : "de-DE",
    "notes" : [ {
      "category" : "legal_disclaimer",
      "text" : "Das BSI ist als Anbieter für die eigenen, zur Nutzung bereitgestellten Inhalte nach den allgemeinen Gesetzen verantwortlich. Nutzerinnen und Nutzer sind jedoch dafür verantwortlich, die Verwendung und/oder die Umsetzung der mit den Inhalten bereitgestellten Informationen sorgfältig im Einzelfall zu prüfen."
    }, {
      "category" : "description",
      "text" : "Der Cisco Application Policy Infrastructure Controller (APIC) ist die architektonische Hauptkomponente der Cisco Application Centric Infrastructure.",
      "title" : "Produktbeschreibung"
    }, {
      "category" : "summary",
      "text" : "Ein Angreifer kann mehrere Schwachstellen in Cisco Application Policy Infrastructure Controller ausnutzen, um sich erweiterte Berechtigungen zu verschaffen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder offenzulegen oder einen Denial-of-Service-Zustand auszulösen.",
      "title" : "Angriff"
    }, {
      "category" : "general",
      "text" : "- CISCO Appliance",
      "title" : "Betroffene Betriebssysteme"
    } ],
    "publisher" : {
      "category" : "other",
      "contact_details" : "csaf-provider@cert-bund.de",
      "name" : "Bundesamt für Sicherheit in der Informationstechnik",
      "namespace" : "https://www.bsi.bund.de"
    },
    "references" : [ {
      "category" : "self",
      "summary" : "WID-SEC-W-2026-3818 - CSAF Version",
      "url" : "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3818.json"
    }, {
      "category" : "self",
      "summary" : "WID-SEC-2026-3818 - Portal Version",
      "url" : "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3818"
    }, {
      "category" : "external",
      "summary" : "Cisco Security Advisory cisco-sa-apic-cmdinj-L6VR4E7 vom 2026-10-07",
      "url" : "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apic-cmdinj-L6VR4E7"
    }, {
      "category" : "external",
      "summary" : "Cisco Security Advisory cisco-sa-apic-info-priv-enAdB5vD vom 2026-10-07",
      "url" : "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apic-info-priv-enAdB5vD"
    }, {
      "category" : "external",
      "summary" : "Cisco Security Advisory cisco-sa-hardening-apic-UOXWtfh vom 2026-10-07",
      "url" : "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-apic-UOXWtfh"
    } ],
    "source_lang" : "en-US",
    "title" : "Cisco Application Policy Infrastructure Controller: Mehrere Schwachstellen",
    "tracking" : {
      "current_release_date" : "2026-10-07T22:00:00.000+00:00",
      "generator" : {
        "date" : "2026-10-08T13:32:14.232+00:00",
        "engine" : {
          "name" : "BSI-WID",
          "version" : "1.6.0"
        }
      },
      "id" : "WID-SEC-W-2026-3818",
      "initial_release_date" : "2026-10-07T22:00:00.000+00:00",
      "revision_history" : [ {
        "date" : "2026-10-07T22:00:00.000+00:00",
        "number" : "1",
        "summary" : "Initiale Fassung"
      } ],
      "status" : "final",
      "version" : "1"
    }
  },
  "product_tree" : {
    "branches" : [ {
      "branches" : [ {
        "branches" : [ {
          "category" : "product_version_range",
          "name" : "<6.0(9h)",
          "product" : {
            "name" : "Cisco Application Policy Infrastructure Controller <6.0(9h)",
            "product_id" : "T060796"
          }
        }, {
          "category" : "product_version",
          "name" : "6.0(9h)",
          "product" : {
            "name" : "Cisco Application Policy Infrastructure Controller 6.0(9h)",
            "product_id" : "T060796-fixed",
            "product_identification_helper" : {
              "cpe" : "cpe:/a:cisco:application_policy_infrastructure_controller:6.0%25289h%2529"
            }
          }
        }, {
          "category" : "product_version_range",
          "name" : "<6.1(6g)",
          "product" : {
            "name" : "Cisco Application Policy Infrastructure Controller <6.1(6g)",
            "product_id" : "T060797"
          }
        }, {
          "category" : "product_version",
          "name" : "6.1(6g)",
          "product" : {
            "name" : "Cisco Application Policy Infrastructure Controller 6.1(6g)",
            "product_id" : "T060797-fixed",
            "product_identification_helper" : {
              "cpe" : "cpe:/a:cisco:application_policy_infrastructure_controller:6.1%25286g%2529"
            }
          }
        }, {
          "category" : "product_version_range",
          "name" : "<6.2(3g)",
          "product" : {
            "name" : "Cisco Application Policy Infrastructure Controller <6.2(3g)",
            "product_id" : "T060798"
          }
        }, {
          "category" : "product_version",
          "name" : "6.2(3g)",
          "product" : {
            "name" : "Cisco Application Policy Infrastructure Controller 6.2(3g)",
            "product_id" : "T060798-fixed",
            "product_identification_helper" : {
              "cpe" : "cpe:/a:cisco:application_policy_infrastructure_controller:6.2%25283g%2529"
            }
          }
        }, {
          "category" : "product_version_range",
          "name" : "<6.1(3f)",
          "product" : {
            "name" : "Cisco Application Policy Infrastructure Controller <6.1(3f)",
            "product_id" : "T060799"
          }
        }, {
          "category" : "product_version",
          "name" : "6.1(3f)",
          "product" : {
            "name" : "Cisco Application Policy Infrastructure Controller 6.1(3f)",
            "product_id" : "T060799-fixed",
            "product_identification_helper" : {
              "cpe" : "cpe:/a:cisco:application_policy_infrastructure_controller:6.1%25283f%2529"
            }
          }
        } ],
        "category" : "product_name",
        "name" : "Application Policy Infrastructure Controller"
      } ],
      "category" : "vendor",
      "name" : "Cisco"
    } ]
  },
  "vulnerabilities" : [ {
    "cve" : "CVE-2026-76498",
    "product_status" : {
      "known_affected" : [ "T060799", "T060798", "T060797", "T060796" ]
    },
    "release_date" : "2026-10-07T22:00:00.000+00:00",
    "title" : "CVE-2026-76498"
  }, {
    "cve" : "CVE-2026-76499",
    "product_status" : {
      "known_affected" : [ "T060799", "T060798", "T060797", "T060796" ]
    },
    "release_date" : "2026-10-07T22:00:00.000+00:00",
    "title" : "CVE-2026-76499"
  }, {
    "cve" : "CVE-2026-76500",
    "product_status" : {
      "known_affected" : [ "T060799", "T060798", "T060797", "T060796" ]
    },
    "release_date" : "2026-10-07T22:00:00.000+00:00",
    "title" : "CVE-2026-76500"
  }, {
    "cve" : "CVE-2026-20321",
    "product_status" : {
      "known_affected" : [ "T060799", "T060798", "T060797", "T060796" ]
    },
    "release_date" : "2026-10-07T22:00:00.000+00:00",
    "title" : "CVE-2026-20321"
  }, {
    "cve" : "CVE-2026-76488",
    "product_status" : {
      "known_affected" : [ "T060799", "T060798", "T060797", "T060796" ]
    },
    "release_date" : "2026-10-07T22:00:00.000+00:00",
    "title" : "CVE-2026-76488"
  } ]
}