CVE-2019-12662 | Cisco NX-OS and IOS XE Software Virtual Service Image Signature Bypass Vulnerability

A vulnerability in Cisco NX-OS Software and Cisco IOS XE Software could allow an authenticated, local attacker with valid administrator or privilege level 15 credentials to load a virtual service image and bypass signature verification on an affected device. The vulnerability is due to improper signature verification during the installation of an Open Virtual Appliance (OVA) image. An authenticated, local attacker could exploit this vulnerability and load a malicious, unsigned OVA image on an affected device. A successful exploit could allow an attacker to perform code execution on a crafted software OVA image.

Published: 2019-09-25 Last update: 2026-06-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2019-12662 is rated Low Risk (34.7/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.30%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2019-12662

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 0.04% 0.30% +0.26%
2 2023-03-07 1.04% 0.04% -0.99%
3 2022-04-01 1.04%

Full EPSS history (6 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2019-12662

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
6.7 3.1 MEDIUM
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Click to expand
Attack vector (AV:L)
They already need access on the box, or another person has to do something wrong; it’s not a remote drive-by.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:H)
They need powerful rights—admin, root, or similar—before this pays off.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:H)
They could widely tamper with or forge data—trust in the data is badly hurt.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
0.8 5.9 [email protected]
6.7 3.0 MEDIUM
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Click to expand
Attack vector (AV:L)
They already need access on the box, or another person has to do something wrong; it’s not a remote drive-by.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:H)
They need powerful rights—admin, root, or similar—before this pays off.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:H)
They could widely tamper with or forge data—trust in the data is badly hurt.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
0.8 5.9 [email protected]
7.2 2.0 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C Click to expand
Access vector (AV:L)
Requires local access to the target system.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:C)
Complete confidentiality impact.
Integrity impact (I:C)
Complete integrity impact.
Availability impact (A:C)
Complete availability impact.
3.9 10.0 [email protected]

Weakness enumeration for CVE-2019-12662

Affected software / configurations for CVE-2019-12662

Vendor Product Version Raw CPE
cisco ios_xe 16.8.1 cpe:2.3:o:cisco:ios_xe:16.8.1:*:*:*:*:*:*:*
cisco nx-os 8.1\(0.2\)s0 cpe:2.3:o:cisco:nx-os:8.1\(0.2\)s0:*:*:*:*:*:*:*
cisco nx-os 8.1\(1\) cpe:2.3:o:cisco:nx-os:8.1\(1\):*:*:*:*:*:*:*
cisco nx-os 8.1\(1\)s5 cpe:2.3:o:cisco:nx-os:8.1\(1\)s5:*:*:*:*:*:*:*
cisco nx-os 8.1\(0\)bd\(0.20\) cpe:2.3:o:cisco:nx-os:8.1\(0\)bd\(0.20\):*:*:*:*:*:*:*
cisco nexus_3016_firmware cpe:2.3:o:cisco:nexus_3016_firmware:-:*:*:*:*:*:*:*
cisco nexus_3048_firmware cpe:2.3:o:cisco:nexus_3048_firmware:-:*:*:*:*:*:*:*
cisco nexus_3064_firmware cpe:2.3:o:cisco:nexus_3064_firmware:-:*:*:*:*:*:*:*
cisco nexus_3064-t_firmware cpe:2.3:o:cisco:nexus_3064-t_firmware:-:*:*:*:*:*:*:*
cisco nexus_31108pc-v_firmware cpe:2.3:o:cisco:nexus_31108pc-v_firmware:-:*:*:*:*:*:*:*
cisco nexus_31108tc-v_firmware cpe:2.3:o:cisco:nexus_31108tc-v_firmware:-:*:*:*:*:*:*:*
cisco nexus_31128pq_firmware cpe:2.3:o:cisco:nexus_31128pq_firmware:-:*:*:*:*:*:*:*
cisco nexus_3132c-z_firmware cpe:2.3:o:cisco:nexus_3132c-z_firmware:-:*:*:*:*:*:*:*
cisco nexus_3132q_firmware cpe:2.3:o:cisco:nexus_3132q_firmware:-:*:*:*:*:*:*:*
cisco nexus_3132q-v_firmware cpe:2.3:o:cisco:nexus_3132q-v_firmware:-:*:*:*:*:*:*:*
cisco nexus_3132q-xl_firmware cpe:2.3:o:cisco:nexus_3132q-xl_firmware:-:*:*:*:*:*:*:*
cisco nexus_3164q_firmware cpe:2.3:o:cisco:nexus_3164q_firmware:-:*:*:*:*:*:*:*
cisco nexus_3172_firmware cpe:2.3:o:cisco:nexus_3172_firmware:-:*:*:*:*:*:*:*
cisco nexus_3172pq-xl_firmware cpe:2.3:o:cisco:nexus_3172pq-xl_firmware:-:*:*:*:*:*:*:*
cisco nexus_3172tq_firmware cpe:2.3:o:cisco:nexus_3172tq_firmware:-:*:*:*:*:*:*:*
cisco nexus_3172tq-32t_firmware cpe:2.3:o:cisco:nexus_3172tq-32t_firmware:-:*:*:*:*:*:*:*
cisco nexus_3172tq-xl_firmware cpe:2.3:o:cisco:nexus_3172tq-xl_firmware:-:*:*:*:*:*:*:*
cisco nexus_3232c_firmware cpe:2.3:o:cisco:nexus_3232c_firmware:-:*:*:*:*:*:*:*
cisco nexus_3264c-e_firmware cpe:2.3:o:cisco:nexus_3264c-e_firmware:-:*:*:*:*:*:*:*
cisco nexus_3264q_firmware cpe:2.3:o:cisco:nexus_3264q_firmware:-:*:*:*:*:*:*:*
cisco nexus_3408-s_firmware cpe:2.3:o:cisco:nexus_3408-s_firmware:-:*:*:*:*:*:*:*
cisco nexus_34180yc_firmware cpe:2.3:o:cisco:nexus_34180yc_firmware:-:*:*:*:*:*:*:*
cisco nexus_34200yc-sm_firmware cpe:2.3:o:cisco:nexus_34200yc-sm_firmware:-:*:*:*:*:*:*:*
cisco nexus_3432d-s_firmware cpe:2.3:o:cisco:nexus_3432d-s_firmware:-:*:*:*:*:*:*:*
cisco nexus_3464c_firmware cpe:2.3:o:cisco:nexus_3464c_firmware:-:*:*:*:*:*:*:*
cisco nexus_3524_firmware cpe:2.3:o:cisco:nexus_3524_firmware:-:*:*:*:*:*:*:*
cisco nexus_3524-x_firmware cpe:2.3:o:cisco:nexus_3524-x_firmware:-:*:*:*:*:*:*:*
cisco nexus_3524-xl_firmware cpe:2.3:o:cisco:nexus_3524-xl_firmware:-:*:*:*:*:*:*:*
cisco nexus_3548_firmware cpe:2.3:o:cisco:nexus_3548_firmware:-:*:*:*:*:*:*:*
cisco nexus_3548-x_firmware cpe:2.3:o:cisco:nexus_3548-x_firmware:-:*:*:*:*:*:*:*
cisco nexus_3548-xl_firmware cpe:2.3:o:cisco:nexus_3548-xl_firmware:-:*:*:*:*:*:*:*
cisco nexus_5548p_firmware cpe:2.3:o:cisco:nexus_5548p_firmware:-:*:*:*:*:*:*:*
cisco nexus_5548up_firmware cpe:2.3:o:cisco:nexus_5548up_firmware:-:*:*:*:*:*:*:*
cisco nexus_5596t_firmware cpe:2.3:o:cisco:nexus_5596t_firmware:-:*:*:*:*:*:*:*
cisco nexus_5596up_firmware cpe:2.3:o:cisco:nexus_5596up_firmware:-:*:*:*:*:*:*:*
cisco nexus_56128p_firmware cpe:2.3:o:cisco:nexus_56128p_firmware:-:*:*:*:*:*:*:*
cisco nexus_5624q_firmware cpe:2.3:o:cisco:nexus_5624q_firmware:-:*:*:*:*:*:*:*
cisco nexus_5648q_firmware cpe:2.3:o:cisco:nexus_5648q_firmware:-:*:*:*:*:*:*:*
cisco nexus_5672up_firmware cpe:2.3:o:cisco:nexus_5672up_firmware:-:*:*:*:*:*:*:*
cisco nexus_5696q_firmware cpe:2.3:o:cisco:nexus_5696q_firmware:-:*:*:*:*:*:*:*
cisco nexus_6001_firmware cpe:2.3:o:cisco:nexus_6001_firmware:-:*:*:*:*:*:*:*
cisco nexus_6004_firmware cpe:2.3:o:cisco:nexus_6004_firmware:-:*:*:*:*:*:*:*
cisco nexus_7000_10-slot_firmware cpe:2.3:o:cisco:nexus_7000_10-slot_firmware:-:*:*:*:*:*:*:*
cisco nexus_7000_18-slot_firmware cpe:2.3:o:cisco:nexus_7000_18-slot_firmware:-:*:*:*:*:*:*:*
cisco nexus_7000_4-slot_firmware cpe:2.3:o:cisco:nexus_7000_4-slot_firmware:-:*:*:*:*:*:*:*
cisco nexus_7000_9-slot_firmware cpe:2.3:o:cisco:nexus_7000_9-slot_firmware:-:*:*:*:*:*:*:*
cisco nexus_7700_10-slot_firmware cpe:2.3:o:cisco:nexus_7700_10-slot_firmware:-:*:*:*:*:*:*:*
cisco nexus_7700_18-slot_firmware cpe:2.3:o:cisco:nexus_7700_18-slot_firmware:-:*:*:*:*:*:*:*
cisco nexus_7700_2-slot_firmware cpe:2.3:o:cisco:nexus_7700_2-slot_firmware:-:*:*:*:*:*:*:*
cisco nexus_7700_6-slot_firmware cpe:2.3:o:cisco:nexus_7700_6-slot_firmware:-:*:*:*:*:*:*:*

References for CVE-2019-12662

cvelogic Threat Intelligence