Cisco Secure Boot Hardware Tampering Vulnerability
A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could allow an authenticated, local attacker to write a modified firmware image to the component. This vulnerability affects multiple Cisco products that support hardware-based Secure Boot functionality. The vulnerability is due to an improper check on the area of code that manages on-premise updates to a Field Programmable Gate Array (FPGA) part of the Secure Boot hardware implementation. An attacker with elevated privileges and access to the underlying operating system that is running on the affected device could exploit this vulnerability by writing a modified firmware image to the FPGA. A successful exploit could either cause the device to become unusable (and require a hardware replacement) or allow tampering with the Secure Boot verification process, which under some circumstances may allow the attacker to install and boot a malicious software image. An attacker will need to fulfill all the following conditions to attempt to exploit this vulnerability: Have privileged administrative access to the device. Be able to access the underlying operating system running on the device; this can be achieved either by using a supported, documented mechanism or by exploiting another vulnerability that would provide an attacker with such access. Develop or have access to a platform-specific exploit. An attacker attempting to exploit this vulnerability across multiple affected platforms would need to research each one of those platforms and then develop a platform-specific exploit. Although the research process could be reused across different platforms, an exploit developed for a given hardware platform is unlikely to work on a different hardware platform.
- Published
- May 13, 2019
- Updated
- Jun 16, 2026
- EPSS
- 0.6% · 48th percentile
- CWE
- CWE-284
Sign in to follow · You’ll be notified if a followed record enters KEV, gets an exploit or is updated.
Report tools
Action score
26
Monitor
Low priority for now.
- CVSS
- 26 / 40 · 6.7 / 10
- CISA KEV
- 0 / 30 · Not listed
- EPSS
- 0 / 30 · 0.6%
CISA SSVC decision
- Exploitation
- none
- Automatable
- no
- Technical impact
- total
Vulnrichment: CISA's decision-tree inputs.
CNA vs NVD score
- NVD
- 6.7
- CNA · cisco
- 6.7
- agree
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The score given by the assigning authority versus NVD’s independent score. A gap means the severity is contested.
Noroxi analysis
No Noroxi analysis for this record yet
We don't hand-write analysis for the hundreds of thousands of vulnerabilities in the database; that wouldn't be honest. For notable, high-impact vulnerabilities our team writes the mechanism, detection and remediation steps.
We use this product, ask for helpAffected systems
| Vendor | Product | CPE |
|---|---|---|
| cisco | asa 5500 firmware | cpe:2.3:o:cisco:asa_5500_firmware |
| cisco | asa 5506-x | cpe:2.3:h:cisco:asa_5506-x |
| cisco | asa 5506h-x | cpe:2.3:h:cisco:asa_5506h-x |
| cisco | asa 5506w-x | cpe:2.3:h:cisco:asa_5506w-x |
| cisco | asa 5508-x | cpe:2.3:h:cisco:asa_5508-x |
| cisco | asa 5516-x | cpe:2.3:h:cisco:asa_5516-x |
| cisco | firepower 2100 firmware | cpe:2.3:o:cisco:firepower_2100_firmware |
| cisco | firepower 2110 | cpe:2.3:h:cisco:firepower_2110 |
| cisco | firepower 2120 | cpe:2.3:h:cisco:firepower_2120 |
| cisco | firepower 2130 | cpe:2.3:h:cisco:firepower_2130 |
| cisco | firepower 2140 | cpe:2.3:h:cisco:firepower_2140 |
| cisco | firepower 4000 firmware | cpe:2.3:o:cisco:firepower_4000_firmware |
and 181 more
Affected versions
NVD version ranges (for catalog products). Add the product to your stack with a version and matching uses these.
- cisco 15454-m-wse-k9 firmwarebefore 11.1
- cisco analog voice network interface modules firmwareall versions
- cisco asa 5500 firmwarebefore 1.1.15
- cisco asr 1000 series firmwareall versions
- cisco asr 1001 firmware16.0.0
- cisco catalyst 9800-40 wireless controller firmwareall versions
- cisco catalyst 9800-80 wireless controller firmwareall versions
- cisco encs 5100 firmwareall versions
- cisco encs 5400 firmwareall versions
- cisco firepower 2100 firmwarebefore 2.6.1.134
- cisco firepower 4000 firmwarebefore 1.0.18
- cisco firepower 9000 firmwarebefore 1.0.18
- cisco ic3000-k9 firmwarebefore 1.0.2
- cisco industrial security appliances 3000 firmwarebefore 1.0.05
- cisco integrated services router 4200 firmwarebefore 1.1
- cisco integrated services router 4300 firmwarebefore 1.1
- cisco integrated services router 4400 firmwarebefore 1.1
- cisco integrated services router t1/e1 voice and wan network interface modules firmwareall versions
- cisco ios15.9 and later · before 15.9\(3\)m
- cisco iosbefore 15.6\(3\)m7
Versions reported by the vendor
Affected version ranges reported by the assigning authority (cisco). Independent of NVD's CPE analysis and usually ahead of it.
Cisco Cisco Routers
- unspecified and later · before 16.12.1affected
Same product
cisco: all recordsOther highest-scoring records for the same primary product.
- CVE-2011-2054Cisco ASA Secondary Authentication Bypass Vulnerability30Monitor
Remediation
Which version to upgrade to
Fix versions compiled from the vendor, package registries and Microsoft. Verify the vendor's note before upgrading.
No fix version is recorded for this entry. Check the references for vendor advisories.
Exploit status
No known public exploit
No public exploit has been observed yet. That doesn't mean you're safe, only that the bar is a little higher.
Research context
For pentesters and researchers: attack profile, score disagreement, timeline, patch commits, credits, variant and chain candidates, bug bounty scope. All derived from existing data; no exploit code.
Timeline
From publication to today: proof of concept, Metasploit module, CISA KEV and fix record. Dates are as reported by the sources.
No dated events beyond publication.
FIRST EPSS daily score; only changes of 0.01 or more are recorded (step chart).
Patch and commit links
Commit, PR and diff links among the references. A starting point for patch-diffing and variant hunting; fixes, not exploits.
No commit or PR link among the references.
Credits
All researchersFinders, reporters and analysts named in the CNA record. Click a name for that researcher’s other records.
No credits in the CNA record.
Variant candidates
Same product, same weakness class, within 18 months. If the patch missed the root cause, the sibling bug is here.
No nightly-computed relations.
Chain candidates
An authentication bypass and a privilege-requiring bug in the same product, published close together: combined they may become an unauthenticated path.
—
Bug bounty scope
No known public program.
Source: bounty-targets-data (public HackerOne, Bugcrowd, Intigriti, YesWeHack listings).
National notice (Türkiye Cybersecurity Directorate / USOM)
Official security notices citing this record; remediation advice is on the agency's page.
- TR-20-145 · Mar 12, 2020(Rockwell Automation Endüstriyel Ürünler Zafiyeti)
- TR-19-076 · Jun 17, 2019(Cisco Güvenlik Güncellemesi Yayınladı)
- TR-19-064 · May 30, 2019(Cisco Güvenlik Güncellemesi Yayınladı)
- TR-19-052 · May 13, 2019(Cisco Güvenlik Güncellemesi Yayınladı)
Technical details
Attack conditions
- Someone with local access to the system can trigger it.
- Administrator privileges are required.
- No user action is required.
- No special conditions are required; it is repeatable.
If successful
- Confidentiality
- high · data can be read
- Integrity
- high · data or configuration can be modified
- Availability
- high · the service can be disrupted
- Attack vector
- Local
- Attack complexity
- Low
- Privileges required
- High
- User interaction
- None
- Scope
- Unchanged
- Confidentiality impact
- High
- Integrity impact
- High
- Availability impact
- High
Weakness class (CWE)
CWE-284 · Improper Access ControlCVSS vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvd-primary
Attack context
MITRE CAPEC attack patterns and ATT&CK techniques for this weakness class (CWE). A starting point for detection rules and threat hunting.
Attack patterns (CAPEC)
- Embedding Scripts within ScriptsCAPEC-19likelihood: High · High
- Malicious Logic InsertionCAPEC-441likelihood: Medium · High
- Modification of Windows Service ConfigurationCAPEC-478likelihood: Low · High
- Malicious Root CertificateCAPEC-479likelihood: Low · Low
- Intent SpoofCAPEC-502
- WebView ExposureCAPEC-503
- Data Injected During ConfigurationCAPEC-536likelihood: Low · High
- Incomplete Data Deletion in a Multi-Tenant EnvironmentCAPEC-546likelihood: Low · Medium
ATT&CK techniques
- RootkitT1014
- Obfuscated Files or Information: Embedded PayloadsT1027.009
- Boot or Logon Initialization ScriptsT1037
- Taint shared contentT1080
- Server Software Component: Terminal Services DLLT1505.005
- Pre-OS Boot:BootkitT1542.003
- Create or Modify System ProcessT1543
- Create or Modify System Process: Launch AgentT1543.001
- Create or Modify System Process:Windows ServiceT1543.003
- Create or Modify System Process: Launch DaemonT1543.004
- Event Triggered Execution:Change Default File AssociationT1546.001
- Event Triggered Execution:.bash_profile and .bashrcT1546.004
- Event Triggered Execution: Accessibility FeaturesT1546.008
- Event Triggered Execution: Installer PackagesT1546.016
- Boot or Logon Autostart ExecutionT1547
- Boot or Logon Autostart Execution:Kernel Modules and ExtensionsT1547.006
Change log
No changes recorded on tracked fields yet. Score, KEV, exploit maturity and fix status changes appear here.
References
- www.securityfocus.com/bid/108350
- tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190513-secureboot
- www.kb.cert.org/vuls/id/400865
- www.us-cert.gov/ics/advisories/icsa-20-072-03
Vendor advisories and official records. Exploit/PoC links are deliberately left out.