CVE-2018-15374
published 2018-10-05CVE-2018-15374: A vulnerability in the Image Verification feature of Cisco IOS XE Software could allow an authenticated, local attacker to install a malicious software image…
PriorityP429medium6.7CVSS 3.0
AVLACLPRHUINSUCHIHAH
EPSS
0.24%
14.7th percentile
A vulnerability in the Image Verification feature of Cisco IOS XE Software could allow an authenticated, local attacker to install a malicious software image or file on an affected device. The vulnerability is due to the affected software improperly verifying digital signatures for software images and files that are uploaded to a device. An attacker could exploit this vulnerability by uploading a malicious software image or file to an affected device. A successful exploit could allow the attacker to bypass digital signature verification checks for software images and files and install a malicious software image or file on the affected device.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_ios_xe_software | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
CVSS provenance
nvdv3.06.7MEDIUMCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco6.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hmgr-779r-qfww: A vulnerability in the Image Verification feature of Cisco IOS XE Software could allow an authenticated, local attacker to install a malicious softwar
ghsa_unreviewed·2022-05-13
CVE-2018-15374 [HIGH] CWE-347 GHSA-hmgr-779r-qfww: A vulnerability in the Image Verification feature of Cisco IOS XE Software could allow an authenticated, local attacker to install a malicious softwar
A vulnerability in the Image Verification feature of Cisco IOS XE Software could allow an authenticated, local attacker to install a malicious software image or file on an affected device. The vulnerability is due to the affected software improperly verifying digital signatures for software images and files that are uploaded to a device. An attacker could exploit this vulnerability by uploading a malicious software image or file to an affected device. A successful exploit could allow the attacker to bypass digital signature verification checks for software images and files and install a malicious software image or file on the affected device.
Cisco
Cisco IOS XE Software Digital Signature Verification Bypass Vulnerability
vendor_cisco·2018-09-26·CVSS 6.7
CVE-2018-15374 [MEDIUM] CWE-347 Cisco IOS XE Software Digital Signature Verification Bypass Vulnerability
Cisco IOS XE Software Digital Signature Verification Bypass Vulnerability
A vulnerability in the Image Verification feature of Cisco IOS XE Software could allow an authenticated, local attacker to install a malicious software image or file on an affected device.
The vulnerability is due to the affected software improperly verifying digital signatures for software images and files that are uploaded to a device. An attacker could exploit this vulnerability by uploading a malicious software image or file to an affected device. A successful exploit could allow the attacker to bypass digital signature verification checks for software images and files and install a malicious software image or file on the affected device.
There are no workarounds that address this vulnerability.
This advisory is
Cisco
Cisco IOS XE Software Digital Signature Verification Bypass Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-15374 Cisco IOS XE Software Digital Signature Verification Bypass Vulnerability
CVE-2018-15374: Cisco IOS XE Software Digital Signature Verification Bypass Vulnerability
A vulnerability in the Image Verification feature of Cisco IOS XE Software could allow an authenticated, local attacker to install a malicious software image or file on an affected device. The vulnerability is due to the affected software improperly verifying digital signatures for software images and files that are uploaded to a device. An attacker could exploit this vulnerability by uploading a malicious software image or file to an affected device. A successful exploit could allow the attacker to bypass digital signature verification checks for software images and files and install a malicious software image or file on the affected device. There are no
CVSS: 3.0
CWE: CWE-347, CWE-347
Bug IDs: CSCvh
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-10-05
Published