6.7
CVE-2019-1808
- EPSS 0.09%
- Veröffentlicht 15.05.2019 23:29:01
- Zuletzt bearbeitet 21.11.2024 04:37:25
- Quelle psirt@cisco.com
- Teams Watchlist Login
- Unerledigt Login
A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an authenticated, local attacker with administrator-level credentials to install a malicious software patch on an affected device. The vulnerability is due to improper verification of digital signatures for patch images. An attacker could exploit this vulnerability by loading an unsigned software patch on an affected device. A successful exploit could allow the attacker to boot a malicious software patch image.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Nx-os Version >= 7.2 < 7.3\(3\)d1\(1\)
Cisco ≫ 7000 10-slot Version-
Cisco ≫ 7000 18-slot Version-
Cisco ≫ 7000 4-slot Version-
Cisco ≫ 7000 9-slot Version-
Cisco ≫ 7700 10-slot Version-
Cisco ≫ 7700 18-slot Version-
Cisco ≫ 7700 2-slot Version-
Cisco ≫ 7700 6-slot Version-
Cisco ≫ N77-f312ck-26 Version-
Cisco ≫ N77-f324fq-25 Version-
Cisco ≫ N77-f348xp-23 Version-
Cisco ≫ N77-f430cq-36 Version-
Cisco ≫ N77-m312cq-26l Version-
Cisco ≫ N77-m324fq-25l Version-
Cisco ≫ N77-m348xp-23l Version-
Cisco ≫ N7k-f248xp-25e Version-
Cisco ≫ N7k-f306ck-25 Version-
Cisco ≫ N7k-f312fq-25 Version-
Cisco ≫ N7k-m202cf-22l Version-
Cisco ≫ N7k-m206fq-23l Version-
Cisco ≫ N7k-m224xp-23l Version-
Cisco ≫ N7k-m324fq-25l Version-
Cisco ≫ N7k-m348xp-25l Version-
Cisco ≫ Nexus 7000 Supervisor 1 Version-
Cisco ≫ Nexus 7000 Supervisor 2 Version-
Cisco ≫ Nexus 7000 Supervisor 2e Version-
Cisco ≫ Nexus 7700 Supervisor 2e Version-
Cisco ≫ Nexus 7700 Supervisor 3e Version-
Cisco ≫ 7000 18-slot Version-
Cisco ≫ 7000 4-slot Version-
Cisco ≫ 7000 9-slot Version-
Cisco ≫ 7700 10-slot Version-
Cisco ≫ 7700 18-slot Version-
Cisco ≫ 7700 2-slot Version-
Cisco ≫ 7700 6-slot Version-
Cisco ≫ N77-f312ck-26 Version-
Cisco ≫ N77-f324fq-25 Version-
Cisco ≫ N77-f348xp-23 Version-
Cisco ≫ N77-f430cq-36 Version-
Cisco ≫ N77-m312cq-26l Version-
Cisco ≫ N77-m324fq-25l Version-
Cisco ≫ N77-m348xp-23l Version-
Cisco ≫ N7k-f248xp-25e Version-
Cisco ≫ N7k-f306ck-25 Version-
Cisco ≫ N7k-f312fq-25 Version-
Cisco ≫ N7k-m202cf-22l Version-
Cisco ≫ N7k-m206fq-23l Version-
Cisco ≫ N7k-m224xp-23l Version-
Cisco ≫ N7k-m324fq-25l Version-
Cisco ≫ N7k-m348xp-25l Version-
Cisco ≫ Nexus 7000 Supervisor 1 Version-
Cisco ≫ Nexus 7000 Supervisor 2 Version-
Cisco ≫ Nexus 7000 Supervisor 2e Version-
Cisco ≫ Nexus 7700 Supervisor 2e Version-
Cisco ≫ Nexus 7700 Supervisor 3e Version-
Cisco ≫ Nx-os Version >= 8.0 < 8.2\(3\)
Cisco ≫ 7000 10-slot Version-
Cisco ≫ 7000 18-slot Version-
Cisco ≫ 7000 4-slot Version-
Cisco ≫ 7000 9-slot Version-
Cisco ≫ 7700 10-slot Version-
Cisco ≫ 7700 18-slot Version-
Cisco ≫ 7700 2-slot Version-
Cisco ≫ 7700 6-slot Version-
Cisco ≫ N77-f312ck-26 Version-
Cisco ≫ N77-f324fq-25 Version-
Cisco ≫ N77-f348xp-23 Version-
Cisco ≫ N77-f430cq-36 Version-
Cisco ≫ N77-m312cq-26l Version-
Cisco ≫ N77-m324fq-25l Version-
Cisco ≫ N77-m348xp-23l Version-
Cisco ≫ N7k-f248xp-25e Version-
Cisco ≫ N7k-f306ck-25 Version-
Cisco ≫ N7k-f312fq-25 Version-
Cisco ≫ N7k-m202cf-22l Version-
Cisco ≫ N7k-m206fq-23l Version-
Cisco ≫ N7k-m224xp-23l Version-
Cisco ≫ N7k-m324fq-25l Version-
Cisco ≫ N7k-m348xp-25l Version-
Cisco ≫ Nexus 7000 Supervisor 1 Version-
Cisco ≫ Nexus 7000 Supervisor 2 Version-
Cisco ≫ Nexus 7000 Supervisor 2e Version-
Cisco ≫ Nexus 7700 Supervisor 2e Version-
Cisco ≫ Nexus 7700 Supervisor 3e Version-
Cisco ≫ 7000 18-slot Version-
Cisco ≫ 7000 4-slot Version-
Cisco ≫ 7000 9-slot Version-
Cisco ≫ 7700 10-slot Version-
Cisco ≫ 7700 18-slot Version-
Cisco ≫ 7700 2-slot Version-
Cisco ≫ 7700 6-slot Version-
Cisco ≫ N77-f312ck-26 Version-
Cisco ≫ N77-f324fq-25 Version-
Cisco ≫ N77-f348xp-23 Version-
Cisco ≫ N77-f430cq-36 Version-
Cisco ≫ N77-m312cq-26l Version-
Cisco ≫ N77-m324fq-25l Version-
Cisco ≫ N77-m348xp-23l Version-
Cisco ≫ N7k-f248xp-25e Version-
Cisco ≫ N7k-f306ck-25 Version-
Cisco ≫ N7k-f312fq-25 Version-
Cisco ≫ N7k-m202cf-22l Version-
Cisco ≫ N7k-m206fq-23l Version-
Cisco ≫ N7k-m224xp-23l Version-
Cisco ≫ N7k-m324fq-25l Version-
Cisco ≫ N7k-m348xp-25l Version-
Cisco ≫ Nexus 7000 Supervisor 1 Version-
Cisco ≫ Nexus 7000 Supervisor 2 Version-
Cisco ≫ Nexus 7000 Supervisor 2e Version-
Cisco ≫ Nexus 7700 Supervisor 2e Version-
Cisco ≫ Nexus 7700 Supervisor 3e Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.09% | 0.221 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 4.4 | 0.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
|
nvd@nist.gov | 2.1 | 3.9 | 2.9 |
AV:L/AC:L/Au:N/C:N/I:P/A:N
|
psirt@cisco.com | 6.7 | 0.8 | 5.9 |
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
CWE-347 Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.