← Back

CVE-2019-1809

nvd nist
Published: May 15, 2019Modified: Nov 21, 2024

JSON object

Loading...
6.7
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.8 / Impact: 5.9
Source: NVD

Description

A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an authenticated, local attacker with administrator-level credentials to install a malicious software patch on an affected device. The vulnerability is due to improper verification of digital signatures for patch images. An attacker could exploit this vulnerability by crafting an unsigned software patch to bypass signature checks and loading it on an affected device. A successful exploit could allow the attacker to boot a malicious software patch image.

Affected (5)

Products: Cisco: Nx Os
1 product
Nx Os
Configuration A
2 vulnerable · 3 platform
Vulnerable SoftwareAffected Versions
Cisco
From 7.3 to 8.1\(1a\)
From 8.2 to 8.3\(1\)
Running on/withPlatform Versions
Cisco
Mds 9706
All versions
Cisco
Mds 9710
All versions
Cisco
Mds 9718
All versions
Configuration B
2 vulnerable · 28 platform
Vulnerable SoftwareAffected Versions
Cisco
From 7.2 to 7.3\(3\)d1\(1\)
From 8.0 to 8.2\(3\)
Running on/withPlatform Versions
Cisco
7000 10 Slot
All versions
Cisco
7000 18 Slot
All versions
Cisco
7000 4 Slot
All versions
Cisco
7000 9 Slot
All versions
Cisco
7700 10 Slot
All versions
Cisco
7700 18 Slot
All versions
Cisco
7700 2 Slot
All versions
Cisco
7700 6 Slot
All versions
Cisco
N77 F312ck 26
All versions
Cisco
N77 F324fq 25
All versions
Cisco
N77 F348xp 23
All versions
Cisco
N77 F430cq 36
All versions
Cisco
N77 M312cq 26l
All versions
Cisco
N77 M324fq 25l
All versions
Cisco
N77 M348xp 23l
All versions
Cisco
N7k F248xp 25e
All versions
Cisco
N7k F306ck 25
All versions
Cisco
N7k F312fq 25
All versions
Cisco
N7k M202cf 22l
All versions
Cisco
N7k M206fq 23l
All versions
Cisco
N7k M224xp 23l
All versions
Cisco
N7k M324fq 25l
All versions
Cisco
N7k M348xp 25l
All versions
Cisco
Nexus 7000 Supervisor 1
All versions
Cisco
Nexus 7000 Supervisor 2
All versions
Cisco
Nexus 7000 Supervisor 2e
All versions
Cisco
Nexus 7700 Supervisor 2e
All versions
Cisco
Nexus 7700 Supervisor 3e
All versions
Configuration C
1 vulnerable · 5 platform
Vulnerable SoftwareAffected Versions
From 3.1 to 3.2\(3k\)
Running on/withPlatform Versions
Cisco
Ucs 6248up
All versions
Cisco
Ucs 6296up
All versions
Cisco
Ucs 6324
All versions
Cisco
Ucs 6332
All versions
Cisco
Ucs 6332 16up
All versions

References (4)

Source: psirt@cisco.com
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry

Timeline

No history available yet.