Rewterz

Rewterz Threat Alert – Rockwell Automation Arena Simulation Software

August 2, 2019
Rewterz

Rewterz Threat Alert – SectorE02 Updates YTY Framework in New Targeted Campaign Against Pakistan Government

August 4, 2019

Rewterz Threat Advisory – CVE2019-1880 – Cisco Unified Computing System BIOS Signature Bypass Vulnerability

Severity

Medium

Analysis Summary

The vulnerability is due to insufficient validation of the firmware image file. An attacker could exploit this vulnerability by executing the BIOS upgrade utility with a specific set of options. A successful exploit could allow the attacker to bypass the firmware signature-verification process and install compromised BIOS firmware on an affected device.

Impact

Security bypass

Affected Vendors

Cisco

Affected Products

Cisco Unified Computing System (UCS) C-Series

Remediation

Please see vendor’s advisory for more details.

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190605-ucs-biossig-bypass

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.