CVE-2018-15374: Cisco IOS XE Software Digital Signature Verification Bypass Vulnerability
A vulnerability in the Image Verification feature of Cisco IOS XE Software could allow an authenticated, local attacker to install a malicious software image or file on an affected device. The vulnerability is due to the affected software improperly verifying digital signatures for software images and files that are uploaded to a device. An attacker could exploit this vulnerability by uploading a malicious software image or file to an affected device. A successful exploit could allow the attacker to bypass digital signature verification checks for software images and files and install a malicious software image or file on the affected device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-15374?
CVE-2018-15374 has a medium severity rating as it allows authenticated local attackers to install malicious software.
How do I fix CVE-2018-15374?
To fix CVE-2018-15374, you should upgrade to a fixed version of Cisco IOS XE Software that properly verifies digital signatures.
What software versions are affected by CVE-2018-15374?
CVE-2018-15374 affects Cisco IOS XE Software version 16.6.1.
Who can exploit CVE-2018-15374?
Only authenticated local attackers can exploit CVE-2018-15374 to install malicious images or files.
What is the cause of the CVE-2018-15374 vulnerability?
The vulnerability in CVE-2018-15374 is caused by the improper verification of digital signatures in the Image Verification feature.