CVE-2019-1649 is a medium-severity vulnerability affecting Cisco products with hardware-based Secure Boot, allowing an authenticated, local attacker to write a modified firmware image to a hardware component due to improper access control logic. Exploitation requires elevated privileges, access to the underlying operating system, and a platform-specific exploit. A successful attack could render the device unusable or compromise the Secure Boot process, potentially allowing malicious software to boot. There is no public exploit code available, it is not actively exploited, and community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.1.15CPE matchmatch criteria | cpe:2.3:o:cisco:asa_5500_firmware:*:*:*:*:*:*:*:* | ||
< 2.6.1.134CPE matchmatch criteria | cpe:2.3:o:cisco:firepower_2100_firmware:*:*:*:*:*:*:*:* | ||
< 1.0.18CPE matchmatch criteria | cpe:2.3:o:cisco:firepower_4000_firmware:*:*:*:*:*:*:*:* | ||
< 1.0.18CPE matchmatch criteria | cpe:2.3:o:cisco:firepower_9000_firmware:*:*:*:*:*:*:*:* | ||
< 11.1CPE matchmatch criteria | cpe:2.3:o:cisco:ons_15454_mstp_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.