CVE-2019-12649
Last modified
CVE-2019-12649 is a medium-severity vulnerability rated 6.7/10 on the CVSS scale. A vulnerability in the Image Verification feature of Cisco IOS XE Software could allow an authenticated, local attacker to install and boot a malicious software image or execute unsigned binaries on an affected device. The vulnerability exists because, under certain circumstances, an affected device can be configured to not verify the digital signatures of system image files during the boot process. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
A vulnerability in the Image Verification feature of Cisco IOS XE Software could allow an authenticated, local attacker to install and boot a malicious software image or execute unsigned binaries on an affected device. The vulnerability exists because, under certain circumstances, an affected device can be configured to not verify the digital signatures of system image files during the boot process. An attacker could exploit this vulnerability by abusing a specific feature that is part of the device boot process. A successful exploit could allow the attacker to install and boot a malicious software image or execute unsigned binaries on the targeted device.
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ios Xe | 16.8\(1\) |
| Cisco | Ios | 16.9.1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-12649?
How severe is CVE-2019-12649?
How do I fix CVE-2019-12649?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-12643A vulnerability in the Cisco REST API virtual service contai…10
- CVE-2019-12644A vulnerability in the web-based management interface of Cis…6.1
- CVE-2019-12645A vulnerability in Cisco Jabber Client Framework (JCF) for M…7.8
- CVE-2019-12646A vulnerability in the Network Address Translation (NAT) Ses…7.5
- CVE-2019-12647A vulnerability in the Ident protocol handler of Cisco IOS a…7.5
- CVE-2019-12648A vulnerability in the IOx application environment for Cisco…8.8
- CVE-2019-1265A security feature bypass vulnerability exists when Microsof…7.5
- CVE-2019-12650Multiple vulnerabilities in the web-based user interface (We…8.8
- CVE-2019-12651Multiple vulnerabilities in the web-based user interface (We…8.8
- CVE-2019-12652A vulnerability in the ingress packet processing function of…7.5
- CVE-2019-12653A vulnerability in the Raw Socket Transport feature of Cisco…7.5
- CVE-2019-12654A vulnerability in the common Session Initiation Protocol (S…7.5
Are you affected by CVE-2019-12649?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
