CVE-2017-12333Improper Verification of Cryptographic Signature in Cisco Nx-os

Severity
6.7MEDIUMNVD
EPSS
0.0%
top 90.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 30
Latest updateMay 17

Description

A vulnerability in Cisco NX-OS System Software could allow an authenticated, local attacker to bypass signature verification when loading a software image. The vulnerability is due to insufficient NX-OS signature verification for software images. An authenticated, local attacker could exploit this vulnerability to bypass signature verification and load a crafted, unsigned software image on a targeted device. The attacker would need valid administrator credentials to perform this exploit. This vu

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.8 | Impact: 5.9

Affected Packages2 packages

NVDcisco/unified_computing_system7.0\(0\)hsk\(0.357\)
NVDcisco/nx-os8.1\(1\)

🔴Vulnerability Details

2
GHSA
GHSA-hq3m-jwg9-rv8q: A vulnerability in Cisco NX-OS System Software could allow an authenticated, local attacker to bypass signature verification when loading a software i2022-05-17
CVEList
CVE-2017-12333: A vulnerability in Cisco NX-OS System Software could allow an authenticated, local attacker to bypass signature verification when loading a software i2017-11-30

📋Vendor Advisories

1
Cisco
Cisco NX-OS System Software Image Signature Bypass Vulnerability2017-11-29
CVE-2017-12333 — Cisco Nx-os vulnerability | cvebase