VDB

CVE-2019-1736

CVE-2019-1736 PUBLISHED CVSS 6.199999809265137 MEDIUM

A vulnerability in the firmware of the Cisco UCS C-Series Rack Servers could allow an authenticated, physical attacker to bypass Unified Extensible Firmware Interface (UEFI) Secure Boot validation checks and load a compromised software image on an affected device. The vulnerability is due to improper validation of the server firmware upgrade images. An attacker could exploit this vulnerability by installing a server firmware version that would allow the attacker to disable UEFI Secure Boot. A successful exploit could allow the attacker to bypass the signature validation checks that are done by UEFI Secure Boot technology and load a compromised software image on the affected device. A compromised software image is any software image that has not been digitally signed by Cisco.

EPSS 0.03% · 10.1th percentile

Risk Scores

CVSS 3.0
6.199999809265137
CVSS:3.0/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.03%
10.1th percentile

Affected Products

VendorProductVersions
ciscosns-3515-k9_firmware0
ciscotg5004-k9_firmware0
ciscosns-3595-k9_firmware0
ciscosns-3515-k9_bios0
ciscosns-3695-k9_bios0
ciscosns-3655-k9_firmware0
ciscofmc2500-k9_bios0
ciscofmc4500-k9_bios0
ciscofmc4500-k9_firmware0
ciscosns-3615-k9_firmware0
ciscotg5004-k9-rf_bios0
ciscofmc1000-k9_bios0
ciscosns-3595-k9_bios0
CiscoCisco Identity Services Engine Softwaren/a
ciscounified_computing_system3.2\(3h\)c
ciscosns-3655-k9_bios0
ciscotg5004-k9_bios0
ciscotg5004-k9-rf_firmware0
ciscoidentity_services_engine2.4\(0.357\), *
ciscofmc1000-k9_firmware0

…and 3 more

Timeline

  • Feb 19, 2020 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Feb 28, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 1, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Nov 6, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›