CVE-2019-1808 describes a vulnerability in the Image Signature Verification feature of Cisco NX-OS Software. This flaw allows an authenticated, local attacker with administrator-level credentials to install a malicious software patch due to improper digital signature verification. A successful exploit could lead to booting an unauthorized software image on affected Cisco devices. The vulnerability has a CVSS score of 4.4 (Medium), indicating a local attack vector with low complexity, requiring high privileges, and resulting in high integrity impact (installation of malicious patches). There is no confidentiality or availability impact. Currently, there is no evidence of active exploitation, nor is there publicly available exploit code in Metasploit or ExploitDB. The CVE has received minimal community discussion and media coverage, suggesting low public awareness and a lack of widespread exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.3, < 8.1\(1a\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:*:*:*:*:*:*:*:* | ||
>= 8.2, < 8.3\(1\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:*:*:*:*:*:*:*:* | ||
>= 7.2, < 7.3\(3\)d1\(1\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:*:*:*:*:*:*:*:* | ||
>= 8.0, < 8.2\(3\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.