VDB

CVE-2019-12662

CVE-2019-12662 PUBLISHED CVSS 6.699999809265137 MEDIUM

A vulnerability in Cisco NX-OS Software and Cisco IOS XE Software could allow an authenticated, local attacker with valid administrator or privilege level 15 credentials to load a virtual service image and bypass signature verification on an affected device. The vulnerability is due to improper signature verification during the installation of an Open Virtual Appliance (OVA) image. An authenticated, local attacker could exploit this vulnerability and load a malicious, unsigned OVA image on an affected device. A successful exploit could allow an attacker to perform code execution on a crafted software OVA image.

EPSS 0.03% · 10.0th percentile

Risk Scores

CVSS 3.0
6.699999809265137
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.03%
10.0th percentile

Affected Products

VendorProductVersions
cisconexus_5624q_firmware
cisconexus_31108pc-v_firmware
cisconexus_3172tq_firmware
cisconexus_3432d-s_firmware
cisconexus_3548-xl_firmware
cisconexus_3524_firmware
cisconexus_6004_firmware
cisconexus_3132q-v_firmware
cisconexus_7000_18-slot_firmware
cisconexus_3264q_firmware
cisconexus_3172_firmware
cisconexus_7700_6-slot_firmware
cisconexus_7000_10-slot_firmware
cisconexus_3408-s_firmware
cisconexus_5696q_firmware
cisconexus_6001_firmware
cisconexus_3048_firmware
cisconexus_3172pq-xl_firmware
cisconexus_34200yc-sm_firmware
cisconexus_5596up_firmware

…and 33 more

Timeline

  • Sep 25, 2019 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 1, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›