CVE-2019-1880
4.4
Vector
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Exploitability: 0.8 / Impact: 3.6
Source: NVD
Description
A vulnerability in the BIOS upgrade utility of Cisco Unified Computing System (UCS) C-Series Rack Servers could allow an authenticated, local attacker to install compromised BIOS firmware on an affected device. The vulnerability is due to insufficient validation of the firmware image file. An attacker could exploit this vulnerability by executing the BIOS upgrade utility with a specific set of options. A successful exploit could allow the attacker to bypass the firmware signature-verification process and install compromised BIOS firmware on an affected device.
Affected (4)
Products: Cisco: Unified Computing System Server Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.0\(2g\) |
| Running on/with | Platform Versions |
|---|---|
Cisco Unified Computing System C125 M5 | All versions |
Configuration B
| Running on/with | Platform Versions |
|---|---|
Cisco Unified Computing System C220 M4 | All versions |
Configuration C
| Running on/with | Platform Versions |
|---|---|
Cisco Unified Computing System C220 M5 | All versions |
Configuration D
| Running on/with | Platform Versions |
|---|---|
Cisco Unified Computing System C240 M4 | All versions |
Configuration E
| Running on/with | Platform Versions |
|---|---|
Cisco Unified Computing System C240 M5 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.0\(4l\) |
| Running on/with | Platform Versions |
|---|---|
Cisco Unified Computing System C460 M4 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.0\(4c\) |
| Running on/with | Platform Versions |
|---|---|
Cisco Unified Computing System C480 M5 | All versions |
References (4)
Source: psirt@cisco.com
Source: psirt@cisco.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.