PT-2019-2365 · Cisco · Cisco Unified Computing System (Ucs) C-Series Rack Servers
Published
2019-06-05
·
Updated
2019-10-09
·
CVE-2019-1880
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:S/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco Unified Computing System (UCS) C-Series Rack Servers (affected versions not specified)
Description
A vulnerability in the BIOS upgrade utility could allow an authenticated, local attacker to install compromised BIOS firmware on an affected device. The issue is due to insufficient validation of the firmware image file. An attacker could exploit this by executing the BIOS upgrade utility with specific options, potentially bypassing the firmware signature-verification process and installing compromised BIOS firmware.
Recommendations
For Cisco Unified Computing System (UCS) C-Series Rack Servers, consider restricting access to the BIOS upgrade utility until a fix is available.
As a temporary workaround, avoid using the BIOS upgrade utility with unverified firmware image files to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Unified Computing System (Ucs) C-Series Rack Servers