Description
A vulnerability in the firmware of the Cisco UCS C-Series Rack Servers could allow an authenticated, physical attacker to bypass Unified Extensible Firmware Interface (UEFI) Secure Boot validation checks and load a compromised software image on an affected device. The vulnerability is due to improper validation of the server firmware upgrade images. An attacker could exploit this vulnerability by installing a server firmware version that would allow the attacker to disable UEFI Secure Boot. A successful exploit could allow the attacker to bypass the signature validation checks that are done by UEFI Secure Boot technology and load a compromised software image on the affected device. A compromised software image is any software image that has not been digitally signed by Cisco.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-10293 | A vulnerability in the firmware of the Cisco UCS C-Series Rack Servers could allow an authenticated, physical attacker to bypass Unified Extensible Firmware Interface (UEFI) Secure Boot validation checks and load a compromised software image on an affected device. The vulnerability is due to improper validation of the server firmware upgrade images. An attacker could exploit this vulnerability by installing a server firmware version that would allow the attacker to disable UEFI Secure Boot. A successful exploit could allow the attacker to bypass the signature validation checks that are done by UEFI Secure Boot technology and load a compromised software image on the affected device. A compromised software image is any software image that has not been digitally signed by Cisco. |
References
History
Wed, 13 Nov 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Subscriptions
Cisco
Subscribe
Fmc1000-k9 Bios
Subscribe
Fmc1000-k9 Firmware
Subscribe
Fmc2500-k9 Bios
Subscribe
Fmc2500-k9 Firmware
Subscribe
Fmc4500-k9 Bios
Subscribe
Fmc4500-k9 Firmware
Subscribe
Identity Services Engine
Subscribe
Sns-3515-k9 Bios
Subscribe
Sns-3515-k9 Firmware
Subscribe
Sns-3595-k9 Bios
Subscribe
Sns-3595-k9 Firmware
Subscribe
Sns-3615-k9 Bios
Subscribe
Sns-3615-k9 Firmware
Subscribe
Sns-3655-k9 Bios
Subscribe
Sns-3655-k9 Firmware
Subscribe
Sns-3695-k9 Bios
Subscribe
Sns-3695-k9 Firmware
Subscribe
Tg5004-k9-rf Bios
Subscribe
Tg5004-k9-rf Firmware
Subscribe
Tg5004-k9 Bios
Subscribe
Tg5004-k9 Firmware
Subscribe
Unified Computing System
Subscribe
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-11-13T18:05:16.337Z
Reserved: 2018-12-06T00:00:00.000Z
Link: CVE-2019-1736
Updated: 2024-08-04T18:28:42.301Z
Status : Modified
Published: 2020-09-23T01:15:14.300
Modified: 2024-11-21T04:37:12.767
Link: CVE-2019-1736
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD