7.2
CVE-2019-12662
- EPSS 0.03%
- Veröffentlicht 25.09.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:23:18
- Quelle psirt@cisco.com
- Teams Watchlist Login
- Unerledigt Login
A vulnerability in Cisco NX-OS Software and Cisco IOS XE Software could allow an authenticated, local attacker with valid administrator or privilege level 15 credentials to load a virtual service image and bypass signature verification on an affected device. The vulnerability is due to improper signature verification during the installation of an Open Virtual Appliance (OVA) image. An authenticated, local attacker could exploit this vulnerability and load a malicious, unsigned OVA image on an affected device. A successful exploit could allow an attacker to perform code execution on a crafted software OVA image.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Nx-os Version8.1(0)bd(0.20)
Cisco ≫ Nexus 9000v Version-
Cisco ≫ Nexus 92160yc-x Version-
Cisco ≫ Nexus 92300yc Version-
Cisco ≫ Nexus 92304qc Version-
Cisco ≫ Nexus 92348gc-x Version-
Cisco ≫ Nexus 9236c Version-
Cisco ≫ Nexus 9272q Version-
Cisco ≫ Nexus 93108tc-ex Version-
Cisco ≫ Nexus 93108tc-fx Version-
Cisco ≫ Nexus 93120tx Version-
Cisco ≫ Nexus 93128tx Version-
Cisco ≫ Nexus 93180lc-ex Version-
Cisco ≫ Nexus 93180yc-ex Version-
Cisco ≫ Nexus 93180yc-fx Version-
Cisco ≫ Nexus 93216tc-fx2 Version-
Cisco ≫ Nexus 93240yc-fx2 Version-
Cisco ≫ Nexus 9332c Version-
Cisco ≫ Nexus 9332pq Version-
Cisco ≫ Nexus 93360yc-fx2 Version-
Cisco ≫ Nexus 9336c-fx2 Version-
Cisco ≫ Nexus 9336pq Aci Spine Version-
Cisco ≫ Nexus 9348gc-fxp Version-
Cisco ≫ Nexus 9364c Version-
Cisco ≫ Nexus 9372px Version-
Cisco ≫ Nexus 9372px-e Version-
Cisco ≫ Nexus 9372tx Version-
Cisco ≫ Nexus 9372tx-e Version-
Cisco ≫ Nexus 9396px Version-
Cisco ≫ Nexus 9396tx Version-
Cisco ≫ Nexus 9504 Version-
Cisco ≫ Nexus 9508 Version-
Cisco ≫ Nexus 9516 Version-
Cisco ≫ Nexus 92160yc-x Version-
Cisco ≫ Nexus 92300yc Version-
Cisco ≫ Nexus 92304qc Version-
Cisco ≫ Nexus 92348gc-x Version-
Cisco ≫ Nexus 9236c Version-
Cisco ≫ Nexus 9272q Version-
Cisco ≫ Nexus 93108tc-ex Version-
Cisco ≫ Nexus 93108tc-fx Version-
Cisco ≫ Nexus 93120tx Version-
Cisco ≫ Nexus 93128tx Version-
Cisco ≫ Nexus 93180lc-ex Version-
Cisco ≫ Nexus 93180yc-ex Version-
Cisco ≫ Nexus 93180yc-fx Version-
Cisco ≫ Nexus 93216tc-fx2 Version-
Cisco ≫ Nexus 93240yc-fx2 Version-
Cisco ≫ Nexus 9332c Version-
Cisco ≫ Nexus 9332pq Version-
Cisco ≫ Nexus 93360yc-fx2 Version-
Cisco ≫ Nexus 9336c-fx2 Version-
Cisco ≫ Nexus 9336pq Aci Spine Version-
Cisco ≫ Nexus 9348gc-fxp Version-
Cisco ≫ Nexus 9364c Version-
Cisco ≫ Nexus 9372px Version-
Cisco ≫ Nexus 9372px-e Version-
Cisco ≫ Nexus 9372tx Version-
Cisco ≫ Nexus 9372tx-e Version-
Cisco ≫ Nexus 9396px Version-
Cisco ≫ Nexus 9396tx Version-
Cisco ≫ Nexus 9504 Version-
Cisco ≫ Nexus 9508 Version-
Cisco ≫ Nexus 9516 Version-
Cisco ≫ Nexus 3016 Firmware Version-
Cisco ≫ Nexus 3048 Firmware Version-
Cisco ≫ Nexus 3064 Firmware Version-
Cisco ≫ Nexus 3064-t Firmware Version-
Cisco ≫ Nexus 31108pc-v Firmware Version-
Cisco ≫ Nexus 31108tc-v Firmware Version-
Cisco ≫ Nexus 31128pq Firmware Version-
Cisco ≫ Nexus 3132c-z Firmware Version-
Cisco ≫ Nexus 3132q Firmware Version-
Cisco ≫ Nexus 3132q-v Firmware Version-
Cisco ≫ Nexus 3132q-xl Firmware Version-
Cisco ≫ Nexus 3164q Firmware Version-
Cisco ≫ Nexus 3172 Firmware Version-
Cisco ≫ Nexus 3172pq-xl Firmware Version-
Cisco ≫ Nexus 3172tq Firmware Version-
Cisco ≫ Nexus 3172tq-32t Firmware Version-
Cisco ≫ Nexus 3172tq-xl Firmware Version-
Cisco ≫ Nexus 3232c Firmware Version-
Cisco ≫ Nexus 3264c-e Firmware Version-
Cisco ≫ Nexus 3264q Firmware Version-
Cisco ≫ Nexus 3408-s Firmware Version-
Cisco ≫ Nexus 34180yc Firmware Version-
Cisco ≫ Nexus 34200yc-sm Firmware Version-
Cisco ≫ Nexus 3432d-s Firmware Version-
Cisco ≫ Nexus 3464c Firmware Version-
Cisco ≫ Nexus 3524 Firmware Version-
Cisco ≫ Nexus 3524-x Firmware Version-
Cisco ≫ Nexus 3524-xl Firmware Version-
Cisco ≫ Nexus 3548 Firmware Version-
Cisco ≫ Nexus 3548-x Firmware Version-
Cisco ≫ Nexus 3548-xl Firmware Version-
Cisco ≫ Nexus 5548p Firmware Version-
Cisco ≫ Nexus 5548up Firmware Version-
Cisco ≫ Nexus 5596t Firmware Version-
Cisco ≫ Nexus 5596up Firmware Version-
Cisco ≫ Nexus 56128p Firmware Version-
Cisco ≫ Nexus 5624q Firmware Version-
Cisco ≫ Nexus 5648q Firmware Version-
Cisco ≫ Nexus 5672up Firmware Version-
Cisco ≫ Nexus 5696q Firmware Version-
Cisco ≫ Nexus 6001 Firmware Version-
Cisco ≫ Nexus 6004 Firmware Version-
Cisco ≫ Nexus 7000 10-slot Firmware Version-
Cisco ≫ Nexus 7000 18-slot Firmware Version-
Cisco ≫ Nexus 7000 4-slot Firmware Version-
Cisco ≫ Nexus 7000 9-slot Firmware Version-
Cisco ≫ Nexus 7700 10-slot Firmware Version-
Cisco ≫ Nexus 7700 18-slot Firmware Version-
Cisco ≫ Nexus 7700 2-slot Firmware Version-
Cisco ≫ Nexus 7700 6-slot Firmware Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.03% | 0.084 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 6.7 | 0.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
psirt@cisco.com | 6.7 | 0.8 | 5.9 |
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
CWE-347 Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.