

Rewterz Threat Advisory – CVE-2019-11634 – Citrix Multiple Products Security Bypass Vulnerability
May 21, 2019
Rewterz Threat Alert – Phishing Campaigns Spoofing Pakistani Banks
May 21, 2019
Rewterz Threat Advisory – CVE-2019-11634 – Citrix Multiple Products Security Bypass Vulnerability
May 21, 2019
Rewterz Threat Alert – Phishing Campaigns Spoofing Pakistani Banks
May 21, 2019Severity
High
Analysis summary
A vulnerability in the logic that handles access control to one of the hardware components in Cisco’s proprietary Secure Boot implementation could allow an authenticated, local attacker to write a modified firmware image to the component.
The vulnerability is due to an improper check on the area of code that manages on-premise updates to a Field Programmable Gate Array (FPGA) part of the Secure Boot hardware implementation. An attacker with elevated privileges and access to the underlying operating system that is running on the affected device could exploit this vulnerability by writing a modified firmware image to the FPGA.
Impact
- Information disclosure
- Entire system being compromised
- Total shutdown of the affected resource
Affected Vendors
Cisco
Affected Products
- Cisco ASA
- Cisco Firepower
Remediation
Updates are available for following products.
Please see vendor’s advisory for the complete list of affected products
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190513-secureboot