VYPR
Unrated severityNVD Advisory· Published Oct 5, 2018· Updated Nov 26, 2024

Cisco Catalyst 6800 Series Switches ROM Monitor Software Secure Boot Bypass Vulnerability

CVE-2018-15370

Description

An unauthenticated local attacker can bypass Cisco Secure Boot on Catalyst 6800 series switches by exploiting a hidden ROMMON command and writing a malicious pattern to memory, allowing a compromised unsigned software image to be loaded.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An unauthenticated local attacker can bypass Cisco Secure Boot on Catalyst 6800 series switches by exploiting a hidden ROMMON command and writing a malicious pattern to memory, allowing a compromised unsigned software image to be loaded.

Vulnerability

A hidden command in Cisco IOS ROM Monitor (ROMMON) Software for Catalyst 6800 Series Switches allows an unauthenticated local attacker to bypass Cisco Secure Boot validation checks [1]. The affected devices include those with Catalyst 6800 Series Supervisor Engine 6T, Catalyst 6840-X Series Fixed Backbone Switches, and Catalyst 6880-X Series Extensible Fixed Aggregation Switches running a vulnerable ROMMON release [1].

Exploitation

An attacker must have physical or console access to the affected device. The attacker connects via the console, forces the device into ROMMON mode, and writes a malicious pattern to a specific memory address on the device [1]. No authentication is required, and no user interaction beyond the initial console connection is needed.

Impact

A successful exploit allows the attacker to bypass signature validation checks by Cisco Secure Boot technology and load a software image that has not been digitally signed by Cisco onto the affected device [1]. This can lead to complete compromise of the device’s trusted boot chain, enabling arbitrary code execution at the firmware level.

Mitigation

Cisco has released software updates to address this vulnerability. Administrators should upgrade to a fixed ROMMON version as recommended in the Cisco Security Advisory [1]. No workarounds are available. The advisory does not indicate the vulnerability is listed on CISA’s Known Exploited Vulnerabilities (KEV) catalog.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

2

News mentions

0

No linked articles in our index yet.