CVE-2019-1809 Details
Description
A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an authenticated, local attacker with administrator-level credentials to install a malicious software patch on an affected device. The vulnerability is due to improper verification of digital signatures for patch images. An attacker could exploit this vulnerability by crafting an unsigned software patch to bypass signature checks and loading it on an affected device. A successful exploit could allow the attacker to boot a malicious software patch image.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Nov 20, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190515-nxos-psvb | CVE | Vendor Advisory |
| http://www.securityfocus.com/bid/108375 | CVE | Broken LinkThird Party AdvisoryVDB Entry |
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190515-nxos-psvb | [email protected] | Vendor Advisory |
| http://www.securityfocus.com/bid/108375 | [email protected] | Broken LinkThird Party AdvisoryVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-347 | Improper Verification of Cryptographic Signature | [email protected] |
| CWE-347 | Improper Verification of Cryptographic Signature | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco nx-os | >= 7.3, < 8.1\(1a\) >= 8.2, < 8.3\(1\) >= 7.2, < 7.3\(3\)d1\(1\) >= 8.0, < 8.2\(3\) >= 3.1, < 3.2\(3k\) |
CPE
Remediation
| |
| cisco mds 9706 | All versions |
CPE
Remediation
| |
| cisco mds 9710 | All versions |
CPE
Remediation
| |
| cisco mds 9718 | All versions |
CPE
Remediation
| |
| cisco 7000 10-slot | All versions |
CPE
Remediation
| |
| cisco 7000 18-slot | All versions |
CPE
Remediation
| |
| cisco 7000 4-slot | All versions |
CPE
Remediation
| |
| cisco 7000 9-slot | All versions |
CPE
Remediation
| |
| cisco 7700 10-slot | All versions |
CPE
Remediation
| |
| cisco 7700 18-slot | All versions |
CPE
Remediation
| |
| cisco 7700 2-slot | All versions |
CPE
Remediation
| |
| cisco 7700 6-slot | All versions |
CPE
Remediation
| |
| cisco n77-f312ck-26 | All versions |
CPE
Remediation
| |
| cisco n77-f324fq-25 | All versions |
CPE
Remediation
| |
| cisco n77-f348xp-23 | All versions |
CPE
Remediation
| |
| cisco n77-f430cq-36 | All versions |
CPE
Remediation
| |
| cisco n77-m312cq-26l | All versions |
CPE
Remediation
| |
| cisco n77-m324fq-25l | All versions |
CPE
Remediation
| |
| cisco n77-m348xp-23l | All versions |
CPE
Remediation
| |
| cisco n7k-f248xp-25e | All versions |
CPE
Remediation
| |
| cisco n7k-f306ck-25 | All versions |
CPE
Remediation
| |
| cisco n7k-f312fq-25 | All versions |
CPE
Remediation
| |
| cisco n7k-m202cf-22l | All versions |
CPE
Remediation
| |
| cisco n7k-m206fq-23l | All versions |
CPE
Remediation
| |
| cisco n7k-m224xp-23l | All versions |
CPE
Remediation
| |
| cisco n7k-m324fq-25l | All versions |
CPE
Remediation
| |
| cisco n7k-m348xp-25l | All versions |
CPE
Remediation
| |
| cisco nexus 7000 supervisor 1 | All versions |
CPE
Remediation
| |
| cisco nexus 7000 supervisor 2 | All versions |
CPE
Remediation
| |
| cisco nexus 7000 supervisor 2e | All versions |
CPE
Remediation
| |
| cisco nexus 7700 supervisor 2e | All versions |
CPE
Remediation
| |
| cisco nexus 7700 supervisor 3e | All versions |
CPE
Remediation
| |
| cisco ucs 6248up | All versions |
CPE
Remediation
| |
| cisco ucs 6296up | All versions |
CPE
Remediation
| |
| cisco ucs 6324 | All versions |
CPE
Remediation
| |
| cisco ucs 6332 | All versions |
CPE
Remediation
| |
| cisco ucs 6332-16up | All versions |
CPE
Remediation
| |
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Mar 24, 2023 | Modified Analysis | [email protected] |
| Oct 9, 2019 | CVE Modified | [email protected] |
| May 20, 2019 | CVE Modified | [email protected] |
| May 17, 2019 | Initial Analysis | [email protected] |