Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p5rq-7r6m-x7rf

Опубликовано: 04 дек. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.2

Описание

A vulnerability in the bootloader of Cisco NX-OS Software could allow an unauthenticated attacker with physical access to an affected device, or an authenticated, local attacker with administrative credentials, to bypass NX-OS image signature verification.

This vulnerability is due to insecure bootloader settings. An attacker could exploit this vulnerability by executing a series of bootloader commands. A successful exploit could allow the attacker to bypass NX-OS image signature verification and load unverified software.

A vulnerability in the bootloader of Cisco NX-OS Software could allow an unauthenticated attacker with physical access to an affected device, or an authenticated, local attacker with administrative credentials, to bypass NX-OS image signature verification.

This vulnerability is due to insecure bootloader settings. An attacker could exploit this vulnerability by executing a series of bootloader commands. A successful exploit could allow the attacker to bypass NX-OS image signature verification and load unverified software.

EPSS

Процентиль: 2%
0.00014
Низкий

5.2 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 5.2
nvd
около 1 года назад

A vulnerability in the bootloader of Cisco NX-OS Software could allow an unauthenticated attacker with physical access to an affected device, or an authenticated, local attacker with administrative credentials, to bypass NX-OS image signature verification.  This vulnerability is due to insecure bootloader settings. An attacker could exploit this vulnerability by executing a series of bootloader commands. A successful exploit could allow the attacker to bypass NX-OS image signature verification and load unverified software.

CVSS3: 5.2
fstec
около 1 года назад

Уязвимость загрузчика операционной системы Cisco NX-OS коммутаторов Cisco Nexus и Cisco UCS Fabric Interconnects, позволяющая нарушителю выполнить произвольные команды

EPSS

Процентиль: 2%
0.00014
Низкий

5.2 Medium

CVSS3

Дефекты

CWE-284