VYPR
Unrated severityNVD Advisory· Published Mar 11, 2019· Updated Nov 20, 2024

Cisco NX-OS Software Image Signature Verification Vulnerability

CVE-2019-1615

Description

A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an authenticated, local attacker with administrator-level credentials to install a malicious software image on an affected device. The vulnerability is due to improper verification of digital signatures for software images. An attacker could exploit this vulnerability by loading an unsigned software image on an affected device. A successful exploit could allow the attacker to boot a malicious software image. Note: The fix for this vulnerability requires a BIOS upgrade as part of the software upgrade. For additional information, see the Details section of this advisory. Nexus 3000 Series Switches are affected running software versions prior to 7.0(3)I7(5). Nexus 9000 Series Fabric Switches in ACI Mode are affected running software versions prior to 13.2(1l). Nexus 9000 Series Switches in Standalone NX-OS Mode are affected running software versions prior to 7.0(3)I7(5). Nexus 9500 R-Series Line Cards and Fabric Modules are affected running software versions prior to 7.0(3)F3(5).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Cisco NX-OS image signature verification flaw allows authenticated local admin to install unsigned malicious images on Nexus switches.

Vulnerability

The vulnerability resides in the Image Signature Verification feature of Cisco NX-OS Software. An authenticated, local attacker with administrator-level credentials can install a malicious unsigned software image on an affected device due to improper verification of digital signatures. Affected products include Nexus 3000 Series Switches running software versions prior to 7.0(3)I7(5), Nexus 9000 Series Fabric Switches in ACI Mode prior to 13.2(1l), Nexus 9000 Series Switches in Standalone NX-OS Mode prior to 7.0(3)I7(5), and Nexus 9500 R-Series Line Cards and Fabric Modules prior to 7.0(3)F3(5). [1]

Exploitation

An attacker must have administrator-level credentials and local access to the device. The exploit involves loading an unsigned software image onto the affected device. The vulnerability is triggered because the device does not properly verify the digital signature of the image, allowing the unsigned image to be accepted. [1]

Impact

Successful exploitation allows the attacker to boot a malicious software image, leading to full compromise of the device's integrity. The attacker can then execute arbitrary code with elevated privileges, potentially gaining persistent control over the device and enabling further network attacks. [1]

Mitigation

Cisco has released fixed software versions: 7.0(3)I7(5) for Nexus 3000 and Nexus 9000 Standalone NX-OS Mode, 13.2(1l) for Nexus 9000 ACI Mode, and 7.0(3)F3(5) for Nexus 9500 R-Series. The fix requires a BIOS upgrade as part of the software upgrade. Customers should upgrade to the appropriate fixed release. No workaround is available. [1]

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

5

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.