Vulnerability Description
A vulnerability in Cisco NX-OS Software and Cisco IOS XE Software could allow an authenticated, local attacker with valid administrator or privilege level 15 credentials to load a virtual service image and bypass signature verification on an affected device. The vulnerability is due to improper signature verification during the installation of an Open Virtual Appliance (OVA) image. An authenticated, local attacker could exploit this vulnerability and load a malicious, unsigned OVA image on an affected device. A successful exploit could allow an attacker to perform code execution on a crafted software OVA image.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ios Xe | 16.8.1 |
| Cisco | Nx-Os | 8.1\(0.2\)s0 |
| Cisco | Mds 9000 | - |
| Cisco | Nexus 9000V | - |
| Cisco | Nexus 92160Yc-X | - |
| Cisco | Nexus 92300Yc | - |
| Cisco | Nexus 92304Qc | - |
| Cisco | Nexus 92348Gc-X | - |
| Cisco | Nexus 9236C | - |
| Cisco | Nexus 9272Q | - |
| Cisco | Nexus 93108Tc-Ex | - |
| Cisco | Nexus 93108Tc-Fx | - |
| Cisco | Nexus 93120Tx | - |
| Cisco | Nexus 93128Tx | - |
| Cisco | Nexus 93180Lc-Ex | - |
| Cisco | Nexus 93180Yc-Ex | - |
| Cisco | Nexus 93180Yc-Fx | - |
| Cisco | Nexus 93216Tc-Fx2 | - |
| Cisco | Nexus 93240Yc-Fx2 | - |
| Cisco | Nexus 9332C | - |
Related Weaknesses (CWE)
References
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-2Vendor Advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-2Vendor Advisory
FAQ
What is CVE-2019-12662?
CVE-2019-12662 is a vulnerability with a CVSS score of 6.7 (MEDIUM). A vulnerability in Cisco NX-OS Software and Cisco IOS XE Software could allow an authenticated, local attacker with valid administrator or privilege level 15 credentials to load a virtual service imag...
How severe is CVE-2019-12662?
CVE-2019-12662 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-12662?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Ios Xe, Cisco Nx-Os, Cisco Mds 9000, Cisco Nexus 9000V, Cisco Nexus 92160Yc-X.