MEDIUM · 4.4

CVE-2019-1880

A vulnerability in the BIOS upgrade utility of Cisco Unified Computing System (UCS) C-Series Rack Servers could allow an authenticated, local attacker to install compromised BIOS firmware on an affect...

Vulnerability Description

A vulnerability in the BIOS upgrade utility of Cisco Unified Computing System (UCS) C-Series Rack Servers could allow an authenticated, local attacker to install compromised BIOS firmware on an affected device. The vulnerability is due to insufficient validation of the firmware image file. An attacker could exploit this vulnerability by executing the BIOS upgrade utility with a specific set of options. A successful exploit could allow the attacker to bypass the firmware signature-verification process and install compromised BIOS firmware on an affected device.

CVSS Score

4.4

MEDIUM

CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
CiscoUnified Computing System Server Firmware< 4.0\(2g\)
CiscoUnified Computing System C125 M5-
CiscoUnified Computing System C220 M4-
CiscoUnified Computing System C220 M5-
CiscoUnified Computing System C240 M4-
CiscoUnified Computing System C240 M5-
CiscoUnified Computing System C460 M4-
CiscoUnified Computing System C480 M5-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-1880?

CVE-2019-1880 is a vulnerability with a CVSS score of 4.4 (MEDIUM). A vulnerability in the BIOS upgrade utility of Cisco Unified Computing System (UCS) C-Series Rack Servers could allow an authenticated, local attacker to install compromised BIOS firmware on an affect...

How severe is CVE-2019-1880?

CVE-2019-1880 has been rated MEDIUM with a CVSS base score of 4.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-1880?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Unified Computing System Server Firmware, Cisco Unified Computing System C125 M5, Cisco Unified Computing System C220 M4, Cisco Unified Computing System C220 M5, Cisco Unified Computing System C240 M4.