PT-2019-1578 · Cisco · Cisco Nx-Os+1

Publicado

2019-03-06

·

Atualizado

2019-10-09

·

CVE-2019-1615

CVSS v2.0

6.8

Média

VetorAV:L/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco NX-OS versions prior to 7.0(3)I7(5) Cisco NX-OS versions prior to 13.2(1l) Cisco NX-OS versions prior to 7.0(3)F3(5)
Description The issue is related to improper verification of digital signatures for software images, which could allow an authenticated, local attacker with administrator-level credentials to install a malicious software image on an affected device. An attacker could exploit this by loading an unsigned software image. A successful exploit could allow the attacker to boot a malicious software image.
Recommendations For Nexus 3000 Series Switches running software versions prior to 7.0(3)I7(5), update to version 7.0(3)I7(5) or later, which includes a BIOS upgrade as part of the software upgrade. For Nexus 9000 Series Fabric Switches in ACI Mode running software versions prior to 13.2(1l), update to version 13.2(1l) or later. For Nexus 9000 Series Switches in Standalone NX-OS Mode running software versions prior to 7.0(3)I7(5), update to version 7.0(3)I7(5) or later. For Nexus 9500 R-Series Line Cards and Fabric Modules running software versions prior to 7.0(3)F3(5), update to version 7.0(3)F3(5) or later.

Correção

Improper Verification of Cryptographic Signature

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-01109
CVE-2019-1615

Produtos afetados

Cisco Nx-Os
Cisco Nexus