CVE-2019-12662: Cisco NX-OS and IOS XE Software Virtual Service Image Signature Bypass Vulnerability
A vulnerability in Cisco NX-OS Software and Cisco IOS XE Software could allow an authenticated, local attacker with valid administrator or privilege level 15 credentials to load a virtual service image and bypass signature verification on an affected device. The vulnerability is due to improper signature verification during the installation of an Open Virtual Appliance (OVA) image. An authenticated, local attacker could exploit this vulnerability and load a malicious, unsigned OVA image on an affected device. A successful exploit could allow an attacker to perform code execution on a crafted software OVA image.
Affected Software
Event History
Frequently Asked Questions
What are the risks associated with CVE-2019-12662?
CVE-2019-12662 allows authenticated local attackers to bypass signature verification and load malicious virtual service images on affected Cisco devices.
What is the severity of CVE-2019-12662?
CVE-2019-12662 is classified as a high severity vulnerability due to its potential impact on device security.
How do I fix CVE-2019-12662?
To mitigate CVE-2019-12662, upgrade Cisco NX-OS Software or Cisco IOS XE Software to the latest fixed versions as recommended by Cisco.
Which Cisco devices are affected by CVE-2019-12662?
CVE-2019-12662 affects specific versions of Cisco NX-OS and Cisco IOS XE Software, primarily 16.8.1 and versions of NX-OS prior to the fixed releases.
Can I exploit CVE-2019-12662 remotely?
No, CVE-2019-12662 requires local access and valid administrative credentials to exploit the vulnerability.