6.9

CVE-2019-1736

A vulnerability in the firmware of the Cisco UCS C-Series Rack Servers could allow an authenticated, physical attacker to bypass Unified Extensible Firmware Interface (UEFI) Secure Boot validation checks and load a compromised software image on an affected device. The vulnerability is due to improper validation of the server firmware upgrade images. An attacker could exploit this vulnerability by installing a server firmware version that would allow the attacker to disable UEFI Secure Boot. A successful exploit could allow the attacker to bypass the signature validation checks that are done by UEFI Secure Boot technology and load a compromised software image on the affected device. A compromised software image is any software image that has not been digitally signed by Cisco.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CiscoFmc1000-k9 Bios Version < 4.0.1f.0
CiscoFmc1000-k9 Firmware Version < 4.0.2h
CiscoFmc2500-k9 Bios Version < 4.0.1f.0
CiscoFmc2500-k9 Firmware Version < 4.0.2h
CiscoFmc4500-k9 Bios Version < 4.0.1f.0
CiscoFmc4500-k9 Firmware Version < 4.0.2h
CiscoSns-3515-k9 Bios Version < 4.0.2d
CiscoSns-3515-k9 Firmware Version < 4.0.2h
CiscoSns-3595-k9 Bios Version < 4.0.2d
CiscoSns-3595-k9 Firmware Version < 4.0.2h
CiscoSns-3615-k9 Bios Version < 4.0.1i
CiscoSns-3615-k9 Firmware Version < 4.0.1g
CiscoSns-3655-k9 Bios Version < 4.0.1i
CiscoSns-3655-k9 Firmware Version < 4.0.1g
CiscoSns-3695-k9 Bios Version < 4.0.1i
CiscoSns-3695-k9 Firmware Version < 4.0.1g
CiscoTg5004-k9 Bios Version < 4.0.2d
CiscoTg5004-k9 Firmware Version < 4.0.2h
CiscoTg5004-k9-rf Bios Version < 4.0.2d
CiscoTg5004-k9-rf Firmware Version < 4.0.2h
CiscoIdentity Services Engine Version2.4(0.357)
CiscoIdentity Services Engine Version2.6(0.156)
CiscoUnified Computing System Version3.2(3h)c
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.03% 0.059
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.6 0.7 5.9
CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.9 3.4 10
AV:L/AC:M/Au:N/C:C/I:C/A:C
psirt@cisco.com 6.2 0.3 5.9
CVSS:3.0/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-347 Improper Verification of Cryptographic Signature

The product does not verify, or incorrectly verifies, the cryptographic signature for data.