CVE-2021-1388

CRITICAL

A vulnerability in an API endpoint of Cisco ACI Multi-Site Orchestrator (MSO) installed on the Application Services Engine could allow an unauthenticated, remote attacker to bypass authentication o...

Affects 2 products across 1 vendor.

BCS7.67
CVSS 3.110.0
EPSS14.8%
Percentile97th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, can impact systems beyond the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-269: Improper Privilege Management

Software does not properly assign, modify, track, or check privileges, allowing unauthorized elevation of access.

Related Attack Patterns (CAPEC)
CAPEC-58 Restful Privilege Elevation
via CWE-269
CAPEC-122 Privilege Abuse
via CWE-269
CAPEC-233 Privilege Escalation
via CWE-269

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ AI Analysis — automated analysis, not human-reviewed

A critical vulnerability in the API endpoint of Cisco ACI Multi-Site Orchestrator (MSO) allows unauthenticated remote attackers to bypass authentication due to improper token validation.

BSID: BS-2021-GLOBAL-081288-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2021-1388?
A critical vulnerability in the API endpoint of Cisco ACI Multi-Site Orchestrator (MSO) allows unauthenticated remote attackers to bypass authentication due to improper token validation.
What is the CVSS score for CVE-2021-1388?
CVE-2021-1388 has CVSS 10.0 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. EPSS: 14.8%.
Is CVE-2021-1388 actively exploited?
No confirmed active exploitation of CVE-2021-1388 as of 2026-09-25.
How do I remediate CVE-2021-1388?
Priority: IMMEDIATE. Advisory: https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-mso-authbyp-bb5GmBQv PSIRT: [email protected]
What systems are affected by CVE-2021-1388?
CVE-2021-1388 affects: Cisco, Cisco.
Vulnerability Details
CVE IDCVE-2021-1388
BSIDBS-2021-GLOBAL-081288-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Published2021-02-24
Last Modified2026-06-17
ICS Relevance70%
Weakness (CWE)
Domains
NETWORK-INFRA
SourceNVD
Official Description

A vulnerability in an API endpoint of Cisco ACI Multi-Site Orchestrator (MSO) installed on the Application Services Engine could allow an unauthenticated, remote attacker to bypass authentication on an affected device. The vulnerability is due to improper token validation on a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted request to the affected API. A successful exploit could allow the attacker to receive a token with administrator-level privileges that could be used to authenticate to the API on affected MSO and managed Cisco Application Policy Infrastructure Controller (APIC) devices.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

An attacker can exploit this vulnerability by sending a crafted request to the affected API endpoint, potentially gaining unauthorized access to the system.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductAffected Versions
Cisco Application Policy Infrastructure Controller 3.0(3i)
Cisco Aci Multi-Site Orchestrator ≥ 3.0, < 3.0(3m)
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: October 2026 | Threat Age: 2049 Days
CISA known-exploitedNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
AI Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash05cbea37b9fe6ab9e47796b39811eb9fd1019bab45761ddef9a6bba65af9cff67d9fd7936fdfca1e8f9759dd283e8becc9b550a30aabf1aec67ea923792f8d6d
Related CVEs affecting Cisco
CVE-2018-0222 10.0 A vulnerability in Cisco Digital Network Architecture (DNA) Center could allo... CVE-2007-2036 10.0 The SNMP implementation in the Cisco Wireless LAN Controller (WLC) before 200... CVE-2018-0101 10.0 A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Ci... CVE-2022-20827 10.0 Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV3... CVE-2008-1157 10.0 Cisco CiscoWorks Internetwork Performance Monitor (IPM) 2.6 creates a process...
View all Cisco CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Create a free account →