EN

Tracker / CVE-2019-1809

CVE-2019-1809

Media 6.7

A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an authenticated, local attacker with administrator-level credentials to install a malicious software patch on an affected device. The vulnerability is due to improper verification of digital signatures for patch images. An attacker could exploit this vulnerability by crafting an unsigned software patch to bypass signature checks and loading it on an affected device. A successful exploit could allow the attacker to boot a malicious software patch image.

Prodotti e versioni affette

cisco nx-os · 3.1 → 3.2\(3k\)
cisco nx-os · 7.2 → 7.3\(3\)d1\(1\)
cisco nx-os · 7.3 → 8.1\(1a\)
cisco nx-os · 8.0 → 8.2\(3\)
cisco nx-os · 8.2 → 8.3\(1\)

Analisi

Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.

Riferimenti