CVE-2019-1811: Cisco NX-OS CLI Command Software Image Signature Verification Vulnerabilities
A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an authenticated, local attacker with administrator-level credentials to install a malicious software image on an affected device. The vulnerability exists because software digital signatures are not properly verified during CLI command execution. An attacker could exploit this vulnerability to install an unsigned software image on an affected device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-1811?
CVE-2019-1811 has a high severity rating, allowing authenticated local attackers to compromise devices by installing malicious software images.
How do I fix CVE-2019-1811?
To mitigate CVE-2019-1811, upgrade the affected Cisco NX-OS Software to a version that addresses this vulnerability.
Which devices are affected by CVE-2019-1811?
CVE-2019-1811 primarily affects Cisco NX-OS Software versions between 6.0(2) and 9.2(2), among other specific device versions.
What type of vulnerability is CVE-2019-1811?
CVE-2019-1811 is a vulnerability in the Image Signature Verification feature of Cisco NX-OS Software.
Can CVE-2019-1811 be exploited remotely?
No, CVE-2019-1811 requires local authenticated access to exploit, making it less likely to be exploited from outside the network.