Unauthenticated Attacker Could Bypass NX-OS Image Signature Verification via Insecure Bootloader Settings
CVE-2024-20397
5.2MEDIUM
Summary
A vulnerability exists in the bootloader of Cisco NX-OS Software that could potentially allow unauthenticated attackers with physical access, or authenticated local attackers with administrative privileges, to bypass the image signature verification process. This issue stems from insecure bootloader settings. By executing specific bootloader commands, an attacker may succeed in loading unverified software, which could compromise the integrity and security of the affected devices. Proper management of bootloader configurations is crucial to mitigate this risk.
References
CVSS V3.1
Score:
5.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published