CVE-2019-1649
published 2019-05-13CVE-2019-1649: A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could allow an…
PriorityP432medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.61%
45.7th percentile
A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could allow an authenticated, local attacker to write a modified firmware image to the component. This vulnerability affects multiple Cisco products that support hardware-based Secure Boot functionality. The vulnerability is due to an improper check on the area of code that manages on-premise updates to a Field Programmable Gate Array (FPGA) part of the Secure Boot hardware implementation. An attacker with elevated privileges and access to the underlying operating system that is running on the affected device could exploit this vulnerability by writing a modified firmware image to the FPGA. A successful exploit could either cause the device to become unusable (and require a hardware replacement) or allow tampering with the Secure Boot verification process, which under some circumstances may allow the attacker to install and boot a malicious software image. An attacker will need to fulfill all the following conditions to attempt to exploit this vulnerability: Have privileged administrative access to the device. Be able to access the underlying operating system running on the device; this can be achieved either by using a supported, documented mechanism or by exploiting another vulnerability that would provide an attacker with such access. Develop or have access to a platform-specific exploit. An attacker attempting to exploit this vulnerability across multiple affected platforms would need to research each one of those platforms and then develop a platform-specific exploit. Although the research process could be reused across different platforms, an exploit developed for a given hardware platform is unlikely to work on a different hardware platform.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | 15454-m-wse-k9_firmware | < 11.1 | 11.1 |
| cisco | asa_5500_firmware | < 1.1.15 | 1.1.15 |
| cisco | asr_1001_firmware | — | — |
| cisco | cisco_routers | >= unspecified < 16.12.1 | 16.12.1 |
| cisco | firepower_2100_firmware | < 2.6.1.134 | 2.6.1.134 |
| cisco | firepower_4000_firmware | < 1.0.18 | 1.0.18 |
| cisco | firepower_9000_firmware | < 1.0.18 | 1.0.18 |
| cisco | ic3000-k9_firmware | < 1.0.2 | 1.0.2 |
| cisco | industrial_security_appliances_3000_firmware | < 1.0.05 | 1.0.05 |
| cisco | integrated_services_router_4200_firmware | < 1.1 | 1.1 |
| cisco | integrated_services_router_4300_firmware | < 1.1 | 1.1 |
| cisco | integrated_services_router_4400_firmware | < 1.1 | 1.1 |
| cisco | ios | < 15.6\(3\)m7 | 15.6\(3\)m7 |
| cisco | ios | < 15.6\(3\)m6b | 15.6\(3\)m6b |
| cisco | ios | 15.7 – 15.7\(3\)m5 | — |
| cisco | ios | 15.7 – 15.7\(3\)m4b | — |
| cisco | ios | >= 15.8 < 15.8\(3\)m3 | 15.8\(3\)m3 |
| cisco | ios | >= 15.8 < 15.8\(3\)m2a | 15.8\(3\)m2a |
| cisco | ios | >= 15.9 < 15.9\(3\)m | 15.9\(3\)m |
| cisco | ios_xe | < 16.12.1 | 16.12.1 |
| cisco | ios_xe | < 16.3.9 | 16.3.9 |
| cisco | ios_xe | < 16.2.1 | 16.2.1 |
| cisco | ios_xe | < 15.5\(1\)sy4 | 15.5\(1\)sy4 |
| cisco | ios_xe | < 16.9.4 | 16.9.4 |
| cisco | ios_xe | >= 16.10 < 16.12.1 | 16.12.1 |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv3.06.7MEDIUMCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco6.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Rockwell Automation Allen-Bradley Stratix 5950
cisa_ics·2020-03-12·CVSS 6.7
[MEDIUM] Rockwell Automation Allen-Bradley Stratix 5950
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Rockwell Automation Allen-Bradley Stratix 5950
Last RevisedMarch 12, 2020
Alert CodeICSA-20-072-03
## 1. EXECUTIVE SUMMARY
- CVSS v3 6.7
- ATTENTION: Exploitable remotely/low skill level to exploit
- Vendor: Rockwell Automation
- Equipment: Allen-Bradley Stratix 5950
- Vulnerability: Improper Access Control
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an attacker to write a modified image to the component.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions of the Allen-Bradley Stratix 5950 Security Appliance are af
Cisco
Cisco Secure Boot Hardware Tampering Vulnerability
vendor_cisco·2019-05-13·CVSS 6.7
CVE-2019-1649 [MEDIUM] CWE-284 Cisco Secure Boot Hardware Tampering Vulnerability
Cisco Secure Boot Hardware Tampering Vulnerability
A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could allow an authenticated, local attacker to write a modified firmware image to the component. This vulnerability affects multiple Cisco products that support hardware-based Secure Boot functionality.
The vulnerability is due to an improper check on the area of code that manages on-premise updates to a Field Programmable Gate Array (FPGA) part of the Secure Boot hardware implementation. An attacker with elevated privileges and access to the underlying operating system that is running on the affected device could exploit this vulnerability by writing a modified firmware image to the FPGA. A success
Cisco
Cisco Secure Boot Hardware Tampering Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-1649 Cisco Secure Boot Hardware Tampering Vulnerability
CVE-2019-1649: Cisco Secure Boot Hardware Tampering Vulnerability
A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could allow an authenticated, local attacker to write a modified firmware image to the component. This vulnerability affects multiple Cisco products that support hardware-based Secure Boot functionality. The vulnerability is due to an improper check on the area of code that manages on-premise updates to a Field Programmable Gate Array (FPGA) part of the Secure Boot hardware implementation. An attacker with elevated privileges and access to the underlying operating system that is running on the affected device could exploit this vulnerability by writing a modified firmware image to the F
GHSA
GHSA-8p3x-34c5-5pmx: A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could all
ghsa_unreviewed·2022-05-24
CVE-2019-1649 [HIGH] CWE-667 GHSA-8p3x-34c5-5pmx: A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could all
A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could allow an authenticated, local attacker to write a modified firmware image to the component. This vulnerability affects multiple Cisco products that support hardware-based Secure Boot functionality. The vulnerability is due to an improper check on the area of code that manages on-premise updates to a Field Programmable Gate Array (FPGA) part of the Secure Boot hardware implementation. An attacker with elevated privileges and access to the underlying operating system that is running on the affected device could exploit this vulnerability by writing a modified firmware image to the FPGA. A successful exploit could either cause the device to become
No detection rules found.
No public exploits indexed.
Tenable
Critical Cisco Vulnerabilities Across Multiple Products, Exploit Code for CVE-2019-1913 Reportedly Released
blogs_tenable·2019-08-22·CVSS 9.8
[CRITICAL] Critical Cisco Vulnerabilities Across Multiple Products, Exploit Code for CVE-2019-1913 Reportedly Released
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Thrangrycat: Vulnerabilities in Cisco Secure Boot and Cisco IOS XE (CVE-2019-1649, CVE-2019-1862)
blogs_tenable·2019-05-14·CVSS 6.7
[MEDIUM] Thrangrycat: Vulnerabilities in Cisco Secure Boot and Cisco IOS XE (CVE-2019-1649, CVE-2019-1862)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bugzilla
CVE-2019-9633 glib: g_socket_client_connected_callback in gio/gsocketclient.c allows to cause denial of service
bugzilla·2019-03-12·CVSS 6.5
CVE-2019-9633 [MEDIUM] CVE-2019-9633 glib: g_socket_client_connected_callback in gio/gsocketclient.c allows to cause denial of service
CVE-2019-9633 glib: g_socket_client_connected_callback in gio/gsocketclient.c allows to cause denial of service
gio/gsocketclient.c in GNOME GLib 2.59.2 does not ensure that a parent GTask remains alive during the execution of a connection-attempting enumeration, which allows remote attackers to cause a denial of service (g_socket_client_connected_callback mishandling and application crash) via a crafted web site, as demonstrated by GNOME Web (aka Epiphany).
Upstream patch:
https://gitlab.gnome.org/GNOME/glib/commit/d553d92d6e9f53cbe5a34166fcb919ba652c6a8e
Upstream issue:
https://gitlab.gnome.org/GNOME/glib/issues/1649
Discussion:
Created glib tracking bugs for this issue:
Affects: epel-all [bug 1687807]
Affects: fedora-all [bug 1687806]
Created glib2 tracking bugs for this issue:
http://www.securityfocus.com/bid/108350https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190513-secureboothttps://www.kb.cert.org/vuls/id/400865https://www.us-cert.gov/ics/advisories/icsa-20-072-03http://www.securityfocus.com/bid/108350https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190513-secureboothttps://www.kb.cert.org/vuls/id/400865https://www.us-cert.gov/ics/advisories/icsa-20-072-03
2019-05-13
Published