Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2019-1810 Details

Description

A vulnerability in the Image Signature Verification feature used in an NX-OS CLI command in Cisco Nexus 3000 Series and 9000 Series Switches could allow an authenticated, local attacker with administrator-level credentials to install a malicious software image on an affected device. The vulnerability exists because software digital signatures are not properly verified during CLI command execution. An attacker could exploit this vulnerability to install an unsigned software image on an affected device. Note: If the device has not been patched for the vulnerability previously disclosed in the Cisco Security Advisory cisco-sa-20190306-nxos-sig-verif, a successful exploit could allow the attacker to boot a malicious software image.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-347Improper Verification of Cryptographic Signature[email protected]
CWE-347Improper Verification of Cryptographic Signature[email protected]

Affected Products

ProductVersions
cisco nx-os
>= 6.1\(2\)i3\(4\), < 7.0\(3\)i7\(5\)
>= 7.0\(3\)i7\(5a\), < 9.2\(2\)
>= 7.0\(3\)i3\(1\), < 7.0\(3\)i7\(1\)
>= 7.0\(3\)i7\(2\), < 9.2\(1\)
>= 7.0\(3\)i4\(1\), < 7.0\(3\)i7\(5\)

CPE

  • cpe:2.3:o:cisco:nx-os:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
cisco n3k-c3164q
All versions

CPE

  • cpe:2.3:h:cisco:n3k-c3164q:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
cisco n3k-c3232c
All versions

CPE

  • cpe:2.3:h:cisco:n3k-c3232c:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
cisco n9k-c92304qc
All versions

CPE

  • cpe:2.3:h:cisco:n9k-c92304qc:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
cisco n9k-c9232c
All versions

CPE

  • cpe:2.3:h:cisco:n9k-c9232c:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

8 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2019-1810
NVD Published Date:
May 15, 2019
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2019-1810 Details - Not Deferred