The Grapevine update process in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.0 allows remote authenticated users to execute arbitrary commands as root via a crafted upgrade parameter, aka Bug ID CSCux15507.Referenceshttp://www.securityfocus.com/bid/92507http://www.securitytracker.com/id/1036634http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160817-apic