CVE-2019-1736
A vulnerability in the firmware of the Cisco UCS C-Series Rack Servers could allow an authenticated, physical attacker to bypass Unified Extensible Firmware Interface (UEFI) Secure Boot validation checks and load a compromised software image on an affected device. The vulnerability is due to improper validation of the server firmware upgrade images. An attacker could exploit this vulnerability by installing a server firmware version that would allow the attacker to disable UEFI Secure Boot. A successful exploit could allow the attacker to bypass the signature validation checks that are done by UEFI Secure Boot technology and load a compromised software image on the affected device. A compromised software image is any software image that has not been digitally signed by Cisco.
EPSS 0.03% · 10.1th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| cisco | sns-3515-k9_firmware | 0 |
| cisco | tg5004-k9_firmware | 0 |
| cisco | sns-3595-k9_firmware | 0 |
| cisco | sns-3515-k9_bios | 0 |
| cisco | sns-3695-k9_bios | 0 |
| cisco | sns-3655-k9_firmware | 0 |
| cisco | fmc2500-k9_bios | 0 |
| cisco | fmc4500-k9_bios | 0 |
| cisco | fmc4500-k9_firmware | 0 |
| cisco | sns-3615-k9_firmware | 0 |
| cisco | tg5004-k9-rf_bios | 0 |
| cisco | fmc1000-k9_bios | 0 |
| cisco | sns-3595-k9_bios | 0 |
| Cisco | Cisco Identity Services Engine Software | n/a |
| cisco | unified_computing_system | 3.2\(3h\)c |
| cisco | sns-3655-k9_bios | 0 |
| cisco | tg5004-k9_bios | 0 |
| cisco | tg5004-k9-rf_firmware | 0 |
| cisco | identity_services_engine | 2.4\(0.357\), * |
| cisco | fmc1000-k9_firmware | 0 |
…and 3 more
Exploit Intelligence
Timeline
- Feb 19, 2020 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Feb 28, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 1, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Nov 6, 2022 EPSS Score