A vulnerability in the BIOS upgrade utility of Cisco Unified Computing System (UCS) C-Series Rack Servers could allow an authenticated, local attacker to install compromised BIOS firmware on an affected device. The vulnerability is due to insufficient validation of the firmware image file. An attacker could exploit this vulnerability by executing the BIOS upgrade utility with a specific set of options. A successful exploit could allow the attacker to bypass the firmware signature-verification process and install compromised BIOS firmware on an affected device.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Cisco
Subscribe
|
Unified Computing System C125 M5
Subscribe
Unified Computing System C220 M4
Subscribe
Unified Computing System C220 M5
Subscribe
Unified Computing System C240 M4
Subscribe
Unified Computing System C240 M5
Subscribe
Unified Computing System C460 M4
Subscribe
Unified Computing System C480 M5
Subscribe
Unified Computing System Server Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-10437 | A vulnerability in the BIOS upgrade utility of Cisco Unified Computing System (UCS) C-Series Rack Servers could allow an authenticated, local attacker to install compromised BIOS firmware on an affected device. The vulnerability is due to insufficient validation of the firmware image file. An attacker could exploit this vulnerability by executing the BIOS upgrade utility with a specific set of options. A successful exploit could allow the attacker to bypass the firmware signature-verification process and install compromised BIOS firmware on an affected device. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-11-21T19:22:52.735Z
Reserved: 2018-12-06T00:00:00
Link: CVE-2019-1880
No data.
Status : Modified
Published: 2019-06-05T17:29:00.647
Modified: 2024-11-21T04:37:36.150
Link: CVE-2019-1880
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD