PT-2019-3332 · Cisco · Cisco Nx-Os+2
Published
2019-09-25
·
Updated
2019-10-09
·
CVE-2019-12662
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco NX-OS Software (affected versions not specified)
Cisco IOS XE Software (affected versions not specified)
Description
A vulnerability in Cisco NX-OS Software and Cisco IOS XE Software could allow an authenticated, local attacker with valid administrator or privilege level 15 credentials to load a virtual service image and bypass signature verification on an affected device. The vulnerability is due to improper signature verification during the installation of an Open Virtual Appliance (OVA) image. An authenticated, local attacker could exploit this vulnerability and load a malicious, unsigned OVA image on an affected device. A successful exploit could allow an attacker to perform code execution on a crafted software OVA image.
Recommendations
For Cisco NX-OS Software, update to a version that includes the fix for this vulnerability.
For Cisco IOS XE Software, update to a version that includes the fix for this vulnerability.
As a temporary workaround, consider restricting the installation of OVA images to minimize the risk of exploitation.
Fix
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Ios Xe
Cisco Nx-Os
Cisco Nexus