A vulnerability in the secure boot process of Cisco FXOS Software could allow an authenticated, local attacker to bypass the secure boot mechanisms. The vulnerability is due to insufficient protections of the secure boot process. An attacker could exploit this vulnerability by injecting code into a specific file that is then referenced during the device boot process. A successful exploit could allow the attacker to break the chain of trust and inject code into the boot process of the device which would be executed at each boot and maintain persistence across reboots.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Cisco
Subscribe
|
Firepower 4110
Subscribe
Firepower 4112
Subscribe
Firepower 4115
Subscribe
Firepower 4120
Subscribe
Firepower 4125
Subscribe
Firepower 4140
Subscribe
Firepower 4145
Subscribe
Firepower 4150
Subscribe
Firepower 9300 Sm-24
Subscribe
Firepower 9300 Sm-36
Subscribe
Firepower 9300 Sm-40
Subscribe
Firepower 9300 Sm-44
Subscribe
Firepower 9300 Sm-44 X 3
Subscribe
Firepower 9300 Sm-48
Subscribe
Firepower 9300 Sm-56
Subscribe
Firepower 9300 Sm-56 X 3
Subscribe
Firepower Extensible Operating System
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-24726 | A vulnerability in the secure boot process of Cisco FXOS Software could allow an authenticated, local attacker to bypass the secure boot mechanisms. The vulnerability is due to insufficient protections of the secure boot process. An attacker could exploit this vulnerability by injecting code into a specific file that is then referenced during the device boot process. A successful exploit could allow the attacker to break the chain of trust and inject code into the boot process of the device which would be executed at each boot and maintain persistence across reboots. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 13 Nov 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2024-11-13T17:48:47.807Z
Reserved: 2019-12-12T00:00:00
Link: CVE-2020-3455
Updated: 2024-08-04T07:37:54.973Z
Status : Modified
Published: 2020-10-21T19:15:16.170
Modified: 2024-11-21T05:31:06.197
Link: CVE-2020-3455
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD