PT-2019-2446 · Cisco · Cisco Secure Boot+1

Madison Oliver

·

Published

2019-05-13

·

Updated

2022-12-13

·

CVE-2019-1649

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco products that support hardware-based Secure Boot functionality (affected versions not specified)
Description A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could allow an authenticated, local attacker to write a modified firmware image to the component. This is due to an improper check on the area of code that manages on-premise updates to a Field Programmable Gate Array (FPGA) part of the Secure Boot hardware implementation. An attacker with elevated privileges and access to the underlying operating system could exploit this vulnerability by writing a modified firmware image to the FPGA. A successful exploit could either cause the device to become unusable or allow tampering with the Secure Boot verification process, potentially allowing the attacker to install and boot a malicious software image. To exploit this vulnerability, an attacker must have privileged administrative access to the device, be able to access the underlying operating system, and develop or have access to a platform-specific exploit.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Improper Locking

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-02224
CVE-2019-1649

Affected Products

Cisco Nexus
Cisco Secure Boot