A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to modify the behavior of default system policies, such as quality of service (QoS) policies, on an affected system. This vulnerability is due to improper access control when restricted security domains are used to implement multi-tenancy. An attacker with a valid user account associated with a restricted security domain could exploit this vulnerability. A successful exploit could allow the attacker to read, modify, or delete child policies created under default system policies, which are implicitly used by all tenants in the fabric, resulting in disruption of network traffic. Exploitation is not possible for policies under tenants that an attacker has no authorization to access.
Conclusion & alert: CVE-2024-20279 is rated Low Risk (34.9/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 0.27%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-11-21 | 0.13% | 0.27% | +0.14% |
| 2 | 2025-11-18 | 0.27% | 0.13% | -0.14% |
| 3 | 2025-10-07 | — | 0.27% | — |
Full EPSS history (6 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 4.3 | 3.1 | MEDIUM |
|
2.8 | 1.4 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| cisco | application_policy_infrastructure_controller | 1.1\(1d\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.1\(1d\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 1.1\(1j\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.1\(1j\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 1.1\(1n\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.1\(1n\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 1.1\(1o\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.1\(1o\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 1.1\(1r\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.1\(1r\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 1.1\(1s\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.1\(1s\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 1.1\(2h\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.1\(2h\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 1.1\(2i\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.1\(2i\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 1.1\(3f\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.1\(3f\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 1.1\(4e\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.1\(4e\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 1.1\(4f\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.1\(4f\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 1.1\(4g\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.1\(4g\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 1.1\(4i\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.1\(4i\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 1.1\(4l\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.1\(4l\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 1.1\(4m\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.1\(4m\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 1.2\(1h\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.2\(1h\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 1.2\(1i\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.2\(1i\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 1.2\(1k\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.2\(1k\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 1.2\(1m\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.2\(1m\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 1.2\(2g\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.2\(2g\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 1.2\(2h\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.2\(2h\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 1.2\(2i\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.2\(2i\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 1.2\(2j\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.2\(2j\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 1.2\(3c\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.2\(3c\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 1.2\(3e\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.2\(3e\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 1.2\(3h\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.2\(3h\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 1.2\(3m\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.2\(3m\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 1.3\(1g\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.3\(1g\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 1.3\(1h\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.3\(1h\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 1.3\(1i\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.3\(1i\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 1.3\(1j\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.3\(1j\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 1.3\(2f\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.3\(2f\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 1.3\(2h\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.3\(2h\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 1.3\(2i\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.3\(2i\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 1.3\(2j\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.3\(2j\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 1.3\(2k\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:1.3\(2k\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 2.0\(1k\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:2.0\(1k\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 2.0\(1l\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:2.0\(1l\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 2.0\(1m\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:2.0\(1m\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 2.0\(1n\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:2.0\(1n\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 2.0\(1o\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:2.0\(1o\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 2.0\(1p\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:2.0\(1p\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 2.0\(1q\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:2.0\(1q\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 2.0\(1r\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:2.0\(1r\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 2.0\(2f\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:2.0\(2f\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 2.0\(2g\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:2.0\(2g\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 2.0\(2h\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:2.0\(2h\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 2.0\(2l\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:2.0\(2l\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 2.0\(2m\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:2.0\(2m\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 2.0\(2n\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:2.0\(2n\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 2.0\(2o\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:2.0\(2o\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 2.1\(1h\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:2.1\(1h\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 2.1\(1i\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:2.1\(1i\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 2.1\(2e\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:2.1\(2e\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 2.1\(2f\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:2.1\(2f\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 2.1\(2g\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:2.1\(2g\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 2.1\(2k\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:2.1\(2k\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 2.1\(3g\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:2.1\(3g\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 2.1\(3h\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:2.1\(3h\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 2.1\(3j\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:2.1\(3j\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 2.1\(4a\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:2.1\(4a\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 2.2\(1k\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:2.2\(1k\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 2.2\(1n\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:2.2\(1n\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 2.2\(1o\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:2.2\(1o\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 2.2\(2e\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:2.2\(2e\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 2.2\(2f\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:2.2\(2f\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 2.2\(2i\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:2.2\(2i\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 2.2\(2j\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:2.2\(2j\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 2.2\(2k\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:2.2\(2k\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 2.2\(2q\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:2.2\(2q\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 2.2\(3j\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:2.2\(3j\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 2.2\(3p\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:2.2\(3p\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 2.2\(3r\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:2.2\(3r\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 2.2\(3s\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:2.2\(3s\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 2.2\(3t\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:2.2\(3t\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 2.2\(4f\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:2.2\(4f\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 2.2\(4p\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:2.2\(4p\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 2.2\(4q\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:2.2\(4q\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 2.2\(4r\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:2.2\(4r\):*:*:*:*:*:*:* |
| cisco | application_policy_infrastructure_controller | 2.3\(1e\) | cpe:2.3:a:cisco:application_policy_infrastructure_controller:2.3\(1e\):*:*:*:*:*:*:* |