PT-2019-3332 · Cisco · Cisco Nx-Os+2

Publicado

2019-09-25

·

Atualizado

2019-10-09

·

CVE-2019-12662

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco NX-OS Software (affected versions not specified) Cisco IOS XE Software (affected versions not specified)
Description A vulnerability in Cisco NX-OS Software and Cisco IOS XE Software could allow an authenticated, local attacker with valid administrator or privilege level 15 credentials to load a virtual service image and bypass signature verification on an affected device. The vulnerability is due to improper signature verification during the installation of an Open Virtual Appliance (OVA) image. An authenticated, local attacker could exploit this vulnerability and load a malicious, unsigned OVA image on an affected device. A successful exploit could allow an attacker to perform code execution on a crafted software OVA image.
Recommendations For Cisco NX-OS Software, update to a version that includes the fix for this vulnerability. For Cisco IOS XE Software, update to a version that includes the fix for this vulnerability. As a temporary workaround, consider restricting the installation of OVA images to minimize the risk of exploitation.

Correção

Improper Verification of Cryptographic Signature

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-03439
CVE-2019-12662

Produtos afetados

Cisco Ios Xe
Cisco Nx-Os
Cisco Nexus