PT-2019-3332 · Cisco · Cisco Nx-Os+2

Published

2019-09-25

·

Updated

2019-10-09

·

CVE-2019-12662

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco NX-OS Software (affected versions not specified) Cisco IOS XE Software (affected versions not specified)
Description A vulnerability in Cisco NX-OS Software and Cisco IOS XE Software could allow an authenticated, local attacker with valid administrator or privilege level 15 credentials to load a virtual service image and bypass signature verification on an affected device. The vulnerability is due to improper signature verification during the installation of an Open Virtual Appliance (OVA) image. An authenticated, local attacker could exploit this vulnerability and load a malicious, unsigned OVA image on an affected device. A successful exploit could allow an attacker to perform code execution on a crafted software OVA image.
Recommendations For Cisco NX-OS Software, update to a version that includes the fix for this vulnerability. For Cisco IOS XE Software, update to a version that includes the fix for this vulnerability. As a temporary workaround, consider restricting the installation of OVA images to minimize the risk of exploitation.

Fix

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-03439
CVE-2019-12662

Affected Products

Cisco Ios Xe
Cisco Nx-Os
Cisco Nexus