CVE-2019-1736: Multiple Cisco UCS-Based Products UEFI Secure Boot Bypass Vulnerability
A vulnerability in the firmware of the Cisco UCS C-Series Rack Servers could allow an authenticated, physical attacker to bypass Unified Extensible Firmware Interface (UEFI) Secure Boot validation checks and load a compromised software image on an affected device. The vulnerability is due to improper validation of the server firmware upgrade images. An attacker could exploit this vulnerability by installing a server firmware version that would allow the attacker to disable UEFI Secure Boot. A successful exploit could allow the attacker to bypass the signature validation checks that are done by UEFI Secure Boot technology and load a compromised software image on the affected device. A compromised software image is any software image that has not been digitally signed by Cisco.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-1736?
CVE-2019-1736 is a vulnerability in the firmware of the Cisco UCS C-Series Rack Servers that allows an authenticated, physical attacker to bypass UEFI Secure Boot validation checks and load a compromised software image on an affected device.
How can an attacker exploit CVE-2019-1736?
An attacker can exploit CVE-2019-1736 by physically accessing the Cisco UCS C-Series Rack Server and bypassing the UEFI Secure Boot validation checks.
What is the severity of CVE-2019-1736?
The severity of CVE-2019-1736 is medium, with a CVSS score of 6.6.
Which Cisco products are affected by CVE-2019-1736?
Cisco UCS C-Series Rack Servers, Cisco Identity Services Engine, and Cisco Unified Computing System are affected by CVE-2019-1736.
How can I fix CVE-2019-1736?
To fix CVE-2019-1736, Cisco recommends upgrading to the appropriate fixed version of the firmware or software.