CVE-2019-12662
Last modified
CVE-2019-12662 is a medium-severity vulnerability rated 6.7/10 on the CVSS scale. A vulnerability in Cisco NX-OS Software and Cisco IOS XE Software could allow an authenticated, local attacker with valid administrator or privilege level 15 credentials to load a virtual service image and bypass signature verification on an affected device. The vulnerability is due to improper signature verification during the installation of an Open Virtual Appliance (OVA) image. EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
A vulnerability in Cisco NX-OS Software and Cisco IOS XE Software could allow an authenticated, local attacker with valid administrator or privilege level 15 credentials to load a virtual service image and bypass signature verification on an affected device. The vulnerability is due to improper signature verification during the installation of an Open Virtual Appliance (OVA) image. An authenticated, local attacker could exploit this vulnerability and load a malicious, unsigned OVA image on an affected device. A successful exploit could allow an attacker to perform code execution on a crafted software OVA image.
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ios Xe | 16.8.1 |
| Cisco | Nx-Os | 8.1\(0.2\)s0 |
| Cisco | Nx-Os | 8.1\(1\) |
| Cisco | Nx-Os | 8.1\(1\)s5 |
| Cisco | Nx-Os | 8.1\(0\)bd\(0.20\) |
| Cisco | Nexus 3016 Firmware | All versions |
| Cisco | Nexus 3048 Firmware | All versions |
| Cisco | Nexus 3064 Firmware | All versions |
| Cisco | Nexus 3064-T Firmware | All versions |
| Cisco | Nexus 31108pc-V Firmware | All versions |
| Cisco | Nexus 31108tc-V Firmware | All versions |
| Cisco | Nexus 31128pq Firmware | All versions |
| Cisco | Nexus 3132c-Z Firmware | All versions |
| Cisco | Nexus 3132q Firmware | All versions |
| Cisco | Nexus 3132q-V Firmware | All versions |
| Cisco | Nexus 3132q-Xl Firmware | All versions |
| Cisco | Nexus 3164q Firmware | All versions |
| Cisco | Nexus 3172 Firmware | All versions |
| Cisco | Nexus 3172pq-Xl Firmware | All versions |
| Cisco | Nexus 3172tq Firmware | All versions |
| Cisco | Nexus 3172tq-32t Firmware | All versions |
| Cisco | Nexus 3172tq-Xl Firmware | All versions |
| Cisco | Nexus 3232c Firmware | All versions |
| Cisco | Nexus 3264c-E Firmware | All versions |
| Cisco | Nexus 3264q Firmware | All versions |
| Cisco | Nexus 3408-S Firmware | All versions |
| Cisco | Nexus 34180yc Firmware | All versions |
| Cisco | Nexus 34200yc-Sm Firmware | All versions |
| Cisco | Nexus 3432d-S Firmware | All versions |
| Cisco | Nexus 3464c Firmware | All versions |
| Cisco | Nexus 3524 Firmware | All versions |
| Cisco | Nexus 3524-X Firmware | All versions |
| Cisco | Nexus 3524-Xl Firmware | All versions |
| Cisco | Nexus 3548 Firmware | All versions |
| Cisco | Nexus 3548-X Firmware | All versions |
| Cisco | Nexus 3548-Xl Firmware | All versions |
| Cisco | Nexus 5548p Firmware | All versions |
| Cisco | Nexus 5548up Firmware | All versions |
| Cisco | Nexus 5596t Firmware | All versions |
| Cisco | Nexus 5596up Firmware | All versions |
| Cisco | Nexus 56128p Firmware | All versions |
| Cisco | Nexus 5624q Firmware | All versions |
| Cisco | Nexus 5648q Firmware | All versions |
| Cisco | Nexus 5672up Firmware | All versions |
| Cisco | Nexus 5696q Firmware | All versions |
| Cisco | Nexus 6001 Firmware | All versions |
| Cisco | Nexus 6004 Firmware | All versions |
| Cisco | Nexus 7000 10-Slot Firmware | All versions |
| Cisco | Nexus 7000 18-Slot Firmware | All versions |
| Cisco | Nexus 7000 4-Slot Firmware | All versions |
Showing 50 of 55 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-12662?
How severe is CVE-2019-12662?
How do I fix CVE-2019-12662?
Are you affected by CVE-2019-12662?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
