PT-2019-14455 · Cisco · Cisco Nexus 9000 Series Fabric Switches
Publicado
2019-05-03
·
Atualizado
2020-10-13
·
CVE-2019-1589
CVSS v3.1
4.6
Média
| Vetor | AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode (affected versions not specified)
Description
The issue is related to the Trusted Platform Module (TPM) functionality, where a lack of proper data-protection mechanisms for disk encryption keys allows an attacker to view sensitive information. An unauthenticated, local attacker with physical access to the device could exploit this by obtaining access to the device to view certain cleartext keys. A successful exploit could allow the attacker to execute a custom boot process or conduct further attacks on the device.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Encryption of Sensitive Data
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Cisco Nexus 9000 Series Fabric Switches