4.4
CVSSv3

CVE-2019-1880

Published: 05/06/2019 Updated: 09/10/2019
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 4.4 | Impact Score: 3.6 | Exploitability Score: 0.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

A vulnerability in the BIOS upgrade utility of Cisco Unified Computing System (UCS) C-Series Rack Servers could allow an authenticated, local malicious user to install compromised BIOS firmware on an affected device. The vulnerability is due to insufficient validation of the firmware image file. An attacker could exploit this vulnerability by executing the BIOS upgrade utility with a specific set of options. A successful exploit could allow the malicious user to bypass the firmware signature-verification process and install compromised BIOS firmware on an affected device.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco unified_computing_system_server_firmware

Vendor Advisories

A vulnerability in the BIOS upgrade utility of Cisco Unified Computing System (UCS) C-Series Rack Servers could allow an authenticated, local attacker to install compromised BIOS firmware on an affected device The vulnerability is due to insufficient validation of the firmware image file An attacker could exploit this vulnerability by executing t ...