CVE-2019-1808
Summary
| CVE | CVE-2019-1808 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-05-15 23:29:00 UTC |
| Updated | 2023-03-24 17:46:00 UTC |
| Description | A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an authenticated, local attacker with administrator-level credentials to install a malicious software patch on an affected device. The vulnerability is due to improper verification of digital signatures for patch images. An attacker could exploit this vulnerability by loading an unsigned software patch on an affected device. A successful exploit could allow the attacker to boot a malicious software patch image. |
Risk And Classification
Problem Types: CWE-347
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Cisco | 7000 10-slot | - | All | All | All |
| Hardware | Cisco | 7000 10-slot | - | All | All | All |
| Hardware | Cisco | 7000 18-slot | - | All | All | All |
| Hardware | Cisco | 7000 18-slot | - | All | All | All |
| Hardware | Cisco | 7000 4-slot | - | All | All | All |
| Hardware | Cisco | 7000 4-slot | - | All | All | All |
| Hardware | Cisco | 7000 9-slot | - | All | All | All |
| Hardware | Cisco | 7000 9-slot | - | All | All | All |
| Hardware | Cisco | 7700 10-slot | - | All | All | All |
| Hardware | Cisco | 7700 10-slot | - | All | All | All |
| Hardware | Cisco | 7700 18-slot | - | All | All | All |
| Hardware | Cisco | 7700 18-slot | - | All | All | All |
| Hardware | Cisco | 7700 2-slot | - | All | All | All |
| Hardware | Cisco | 7700 2-slot | - | All | All | All |
| Hardware | Cisco | 7700 6-slot | - | All | All | All |
| Hardware | Cisco | 7700 6-slot | - | All | All | All |
| Hardware | Cisco | Mds 9706 | - | All | All | All |
| Hardware | Cisco | Mds 9706 | - | All | All | All |
| Hardware | Cisco | Mds 9710 | - | All | All | All |
| Hardware | Cisco | Mds 9710 | - | All | All | All |
| Hardware | Cisco | Mds 9718 | - | All | All | All |
| Hardware | Cisco | Mds 9718 | - | All | All | All |
| Hardware | Cisco | N77-f312ck-26 | - | All | All | All |
| Hardware | Cisco | N77-f312ck-26 | - | All | All | All |
| Hardware | Cisco | N77-f324fq-25 | - | All | All | All |
| Hardware | Cisco | N77-f324fq-25 | - | All | All | All |
| Hardware | Cisco | N77-f348xp-23 | - | All | All | All |
| Hardware | Cisco | N77-f348xp-23 | - | All | All | All |
| Hardware | Cisco | N77-f430cq-36 | - | All | All | All |
| Hardware | Cisco | N77-f430cq-36 | - | All | All | All |
| Hardware | Cisco | N77-m312cq-26l | - | All | All | All |
| Hardware | Cisco | N77-m312cq-26l | - | All | All | All |
| Hardware | Cisco | N77-m324fq-25l | - | All | All | All |
| Hardware | Cisco | N77-m324fq-25l | - | All | All | All |
| Hardware | Cisco | N77-m348xp-23l | - | All | All | All |
| Hardware | Cisco | N77-m348xp-23l | - | All | All | All |
| Hardware | Cisco | N7k-f248xp-25e | - | All | All | All |
| Hardware | Cisco | N7k-f248xp-25e | - | All | All | All |
| Hardware | Cisco | N7k-f306ck-25 | - | All | All | All |
| Hardware | Cisco | N7k-f306ck-25 | - | All | All | All |
| Hardware | Cisco | N7k-f312fq-25 | - | All | All | All |
| Hardware | Cisco | N7k-f312fq-25 | - | All | All | All |
| Hardware | Cisco | N7k-m202cf-22l | - | All | All | All |
| Hardware | Cisco | N7k-m202cf-22l | - | All | All | All |
| Hardware | Cisco | N7k-m206fq-23l | - | All | All | All |
| Hardware | Cisco | N7k-m206fq-23l | - | All | All | All |
| Hardware | Cisco | N7k-m224xp-23l | - | All | All | All |
| Hardware | Cisco | N7k-m224xp-23l | - | All | All | All |
| Hardware | Cisco | N7k-m324fq-25l | - | All | All | All |
| Hardware | Cisco | N7k-m324fq-25l | - | All | All | All |
| Hardware | Cisco | N7k-m348xp-25l | - | All | All | All |
| Hardware | Cisco | N7k-m348xp-25l | - | All | All | All |
| Hardware | Cisco | Nexus 7000 Supervisor 1 | - | All | All | All |
| Hardware | Cisco | Nexus 7000 Supervisor 1 | - | All | All | All |
| Hardware | Cisco | Nexus 7000 Supervisor 2 | - | All | All | All |
| Hardware | Cisco | Nexus 7000 Supervisor 2 | - | All | All | All |
| Hardware | Cisco | Nexus 7000 Supervisor 2e | - | All | All | All |
| Hardware | Cisco | Nexus 7000 Supervisor 2e | - | All | All | All |
| Hardware | Cisco | Nexus 7700 Supervisor 2e | - | All | All | All |
| Hardware | Cisco | Nexus 7700 Supervisor 2e | - | All | All | All |
| Hardware | Cisco | Nexus 7700 Supervisor 3e | - | All | All | All |
| Hardware | Cisco | Nexus 7700 Supervisor 3e | - | All | All | All |
| Operating System | Cisco | Nx-os | All | All | All | All |
| Operating System | Cisco | Nx-os | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Malformed Request | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Cisco MDS 9700 Series Multilayer Directors and Nexus 7000/7700 Series Switches Software Patch Signature Verification Vulnerability | CISCO | tools.cisco.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.