Vulnerability Description
A vulnerability in the BIOS upgrade utility of Cisco Unified Computing System (UCS) C-Series Rack Servers could allow an authenticated, local attacker to install compromised BIOS firmware on an affected device. The vulnerability is due to insufficient validation of the firmware image file. An attacker could exploit this vulnerability by executing the BIOS upgrade utility with a specific set of options. A successful exploit could allow the attacker to bypass the firmware signature-verification process and install compromised BIOS firmware on an affected device.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Unified Computing System Server Firmware | < 4.0\(2g\) |
| Cisco | Unified Computing System C125 M5 | - |
| Cisco | Unified Computing System C220 M4 | - |
| Cisco | Unified Computing System C220 M5 | - |
| Cisco | Unified Computing System C240 M4 | - |
| Cisco | Unified Computing System C240 M5 | - |
| Cisco | Unified Computing System C460 M4 | - |
| Cisco | Unified Computing System C480 M5 | - |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/108680
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-2Vendor Advisory
- http://www.securityfocus.com/bid/108680
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-2Vendor Advisory
FAQ
What is CVE-2019-1880?
CVE-2019-1880 is a vulnerability with a CVSS score of 4.4 (MEDIUM). A vulnerability in the BIOS upgrade utility of Cisco Unified Computing System (UCS) C-Series Rack Servers could allow an authenticated, local attacker to install compromised BIOS firmware on an affect...
How severe is CVE-2019-1880?
CVE-2019-1880 has been rated MEDIUM with a CVSS base score of 4.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-1880?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Unified Computing System Server Firmware, Cisco Unified Computing System C125 M5, Cisco Unified Computing System C220 M4, Cisco Unified Computing System C220 M5, Cisco Unified Computing System C240 M4.