CVE-2019-1649

Description

A vulnerability in the logic that handles access control to one of the hardware components in Ciscos proprietary Secure Boot implementation could allow an authenticated, local attacker to write a modified firmware image to the component. This vulnerability affects multiple Cisco products that support hardware-based Secure Boot functionality. The vulnerability is due to an improper check on the area of code that manages on-premise updates to a Field Programmable Gate Array (FPGA) part of the Secure Boot hardware implementation. An attacker with elevated privileges and access to the underlying operating system that is running on the affected device could exploit this vulnerability by writing a modified firmware image to the FPGA. A successful exploit could either cause the device to become unusable (and require a hardware replacement) or allow tampering with the Secure Boot verification process, which under some circumstances may allow the attacker to install and boot a malicious software image. An attacker will need to fulfill all the following conditions to attempt to exploit this vulnerability: Have privileged administrative access to the device. Be able to access the underlying operating system running on the device; this can be achieved either by using a supported, documented mechanism or by exploiting another vulnerability that would provide an attacker with such access. Develop or have access to a platform-specific exploit. An attacker attempting to exploit this vulnerability across multiple affected platforms would need to research each one of those platforms and then develop a platform-specific exploit. Although the research process could be reused across different platforms, an exploit developed for a given hardware platform is unlikely to work on a different hardware platform.

Risk Information

Base Score
6.7
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.341

Associated Vulnerability

VulnerabilityOS Platform
Cisco Secure Boot Hardware Tampering Vulnerability For Cisco 5000 Series Enterprise Network Compute SystemNCM
Cisco Secure Boot Hardware Tampering Vulnerability For Cisco ASR 9000 Series Aggregation Services RoutersNCM
Cisco Secure Boot Hardware Tampering Vulnerability For Cisco Catalyst 9500 Series SwitchesNCM
Cisco Secure Boot Hardware Tampering Vulnerability For Cisco Nexus 9000 Series SwitchesNCM
Cisco Secure Boot Hardware Tampering Vulnerability For Cisco Nexus 7000 10-Slot SwitchNCM
Cisco Secure Boot Hardware Tampering Vulnerability For Cisco Nexus 7000 18-Slot SwitchNCM
Cisco Secure Boot Hardware Tampering Vulnerability For Cisco Nexus 7000 9-Slot SwitchNCM
Cisco Secure Boot Hardware Tampering Vulnerability For Cisco Nexus 7000 4-Slot SwitchNCM
Cisco Secure Boot Hardware Tampering Vulnerability For Cisco MDS 9710 Multilayer DirectorNCM
Cisco Secure Boot Hardware Tampering Vulnerability For Cisco MDS 9250i Multiservice Fabric SwitchNCM
Cisco Secure Boot Hardware Tampering Vulnerability For Cisco Nexus 7700 10-Slot SwitchNCM
Cisco Secure Boot Hardware Tampering Vulnerability For Cisco Nexus 7700 18-Slot SwitchNCM
Cisco Secure Boot Hardware Tampering Vulnerability For Cisco Nexus 7700 6-Slot SwitchNCM
Cisco Secure Boot Hardware Tampering Vulnerability For Cisco MDS 9148S 16G Multilayer Fabric SwitchNCM
Cisco Secure Boot Hardware Tampering Vulnerability For Cisco MDS 9706 Multilayer DirectorNCM
Cisco Secure Boot Hardware Tampering Vulnerability For Cisco Nexus 7700 2-Slot SwitchNCM
Cisco Secure Boot Hardware Tampering Vulnerability For Cisco MDS 9396S 16G Multilayer Fabric SwitchNCM
Cisco Secure Boot Hardware Tampering Vulnerability For Cisco MDS 9132T 32-Gbps 32-Port Fibre Channel SwitchNCM
Cisco Secure Boot Hardware Tampering Vulnerability For Cisco MDS 9148T 32-Gbps 48-Port Fibre Channel SwitchNCM
Cisco Secure Boot Hardware Tampering Vulnerability For Cisco MDS 9396T 32-Gbps 96-Port Fibre Channel SwitchNCM
Cisco Secure Boot Hardware Tampering Vulnerability For NCM
Cisco Secure Boot Hardware Tampering Vulnerability For Cisco 1000 Series RoutersNCM
Cisco Secure Boot Hardware Tampering Vulnerability For Cisco ONS 15454 Series Multiservice Provisioning PlatformsNCM
Cisco Secure Boot Hardware Tampering Vulnerability For Cisco Application Extension PlatformNCM
Cisco Secure Boot Hardware Tampering Vulnerability For CiscoPro Workgroup EtherSwitch SoftwareNCM
Improper Locking Vulnerability (CVE-2019-1649)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1700011Security Update for Cisco 5000 Series Enterprise Network Compute System 4.1(1c)
PATCH-1705564Security Update for Cisco ASR 9000 Series Aggregation Services Routers 5.3.0.1i.BASE
PATCH-1705904Security Update for Cisco Catalyst 9500 Series Switches Denali-16.3.4a
PATCH-1706000Security Update for Cisco Nexus 9000 Series Switches 15.1(4c)
PATCH-1705011Security Update for Cisco Nexus 7000 10-Slot Switch 8.4(2)
PATCH-1705012Security Update for Cisco Nexus 7000 18-Slot Switch 8.4(2)
PATCH-1705013Security Update for Cisco Nexus 7000 9-Slot Switch 8.4(2)
PATCH-1705014Security Update for Cisco Nexus 7000 4-Slot Switch 8.4(2)
PATCH-1705015Security Update for Cisco MDS 9710 Multilayer Director 8.4(2)
PATCH-1705016Security Update for Cisco MDS 9250i Multiservice Fabric Switch 8.4(2)
PATCH-1705017Security Update for Cisco Nexus 7700 10-Slot Switch 8.4(2)
PATCH-1705018Security Update for Cisco Nexus 7700 18-Slot Switch 8.4(2)
PATCH-1705019Security Update for Cisco Nexus 7700 6-Slot Switch 8.4(2)
PATCH-1705020Security Update for Cisco MDS 9148S 16G Multilayer Fabric Switch 8.4(2)
PATCH-1705021Security Update for Cisco MDS 9706 Multilayer Director 8.4(2)
PATCH-1705022Security Update for Cisco Nexus 7700 2-Slot Switch 8.4(2)
PATCH-1705023Security Update for Cisco MDS 9396S 16G Multilayer Fabric Switch 8.4(2)
PATCH-1705024Security Update for Cisco MDS 9132T 32-Gbps 32-Port Fibre Channel Switch 8.4(2)
PATCH-1705025Security Update for Cisco MDS 9148T 32-Gbps 48-Port Fibre Channel Switch 8.4(2)
PATCH-1705026Security Update for Cisco MDS 9396T 32-Gbps 96-Port Fibre Channel Switch 8.4(2)
PATCH-1706026Security Update for CAF-1.2.0.0
PATCH-1705963Security Update for Cisco ONS 15454 Series Multiservice Provisioning Platforms 10.6(2)
PATCH-1705914Security Update for Cisco Application Extension Platform 1.0.3.16
PATCH-1706035Security Update for CiscoPro Workgroup EtherSwitch Software 6.0(2)A8(4)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234