CVE-2019-1649 | Cisco Secure Boot Hardware Tampering Vulnerability

A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could allow an authenticated, local attacker to write a modified firmware image to the component. This vulnerability affects multiple Cisco products that support hardware-based Secure Boot functionality. The vulnerability is due to an improper check on the area of code that manages on-premise updates to a Field Programmable Gate Array (FPGA) part of the Secure Boot hardware implementation. An attacker with elevated privileges and access to the underlying operating system that is running on the affected device could exploit this vulnerability by writing a modified firmware image to the FPGA. A successful exploit could either cause the device to become unusable (and require a hardware replacement) or allow tampering with the Secure Boot verification process, which under some circumstances may allow the attacker to install and boot a malicious software image. An attacker will need to fulfill all the following conditions to attempt to exploit this vulnerability: Have privileged administrative access to the device. Be able to access the underlying operating system running on the device; this can be achieved either by using a supported, documented mechanism or by exploiting another vulnerability that would provide an attacker with such access. Develop or have access to a platform-specific exploit. An attacker attempting to exploit this vulnerability across multiple affected platforms would need to research each one of those platforms and then develop a platform-specific exploit. Although the research process could be reused across different platforms, an exploit developed for a given hardware platform is unlikely to work on a different hardware platform.

Published: 2019-05-13 Last update: 2026-06-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2019-1649 is rated Moderate Risk (42.6/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.61%). Mandatory action: Review affected assets and schedule remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2019-1649

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 0.40% 0.61% +0.21%
2 2026-03-18 0.35% 0.40% +0.05%
3 2026-01-25 0.35%

Full EPSS history (18 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2019-1649

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
6.7 3.1 MEDIUM
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Click to expand
Attack vector (AV:L)
They already need access on the box, or another person has to do something wrong; it’s not a remote drive-by.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:H)
They need powerful rights—admin, root, or similar—before this pays off.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:H)
They could widely tamper with or forge data—trust in the data is badly hurt.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
0.8 5.9 [email protected]
6.7 3.0 MEDIUM
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Click to expand
Attack vector (AV:L)
They already need access on the box, or another person has to do something wrong; it’s not a remote drive-by.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:H)
They need powerful rights—admin, root, or similar—before this pays off.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:H)
They could widely tamper with or forge data—trust in the data is badly hurt.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
0.8 5.9 [email protected]
7.2 2.0 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C Click to expand
Access vector (AV:L)
Requires local access to the target system.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:C)
Complete confidentiality impact.
Integrity impact (I:C)
Complete integrity impact.
Availability impact (A:C)
Complete availability impact.
3.9 10.0 [email protected]

Weakness enumeration for CVE-2019-1649

Affected software / configurations for CVE-2019-1649

Vendor Product Version Raw CPE
cisco asa_5500_firmware < 1.1.15 cpe:2.3:o:cisco:asa_5500_firmware:*:*:*:*:*:*:*:*
cisco firepower_2100_firmware < 2.6.1.134 cpe:2.3:o:cisco:firepower_2100_firmware:*:*:*:*:*:*:*:*
cisco firepower_4000_firmware < 1.0.18 cpe:2.3:o:cisco:firepower_4000_firmware:*:*:*:*:*:*:*:*
cisco firepower_9000_firmware < 1.0.18 cpe:2.3:o:cisco:firepower_9000_firmware:*:*:*:*:*:*:*:*
cisco ons_15454_mstp_firmware < 11.1 cpe:2.3:o:cisco:ons_15454_mstp_firmware:*:*:*:*:*:*:*:*
cisco analog_voice_network_interface_modules_firmware cpe:2.3:o:cisco:analog_voice_network_interface_modules_firmware:*:*:*:*:*:*:4000_series_isrs:*
cisco integrated_services_router_t1\/e1_voice_and_wan_network_interface_modules_firmware cpe:2.3:o:cisco:integrated_services_router_t1\/e1_voice_and_wan_network_interface_modules_firmware:*:*:*:*:*:*:4000_series:*
cisco supervisor_a\+_firmware cpe:2.3:o:cisco:supervisor_a\+_firmware:*:*:*:*:*:*:nexus_9500:*
cisco supervisor_b\+_firmware cpe:2.3:o:cisco:supervisor_b\+_firmware:*:*:*:*:*:*:nexus_9500:*
cisco 15454-m-wse-k9_firmware < 11.1 cpe:2.3:o:cisco:15454-m-wse-k9_firmware:*:*:*:*:*:*:*:*
cisco ios_xe < 16.12.1 cpe:2.3:o:cisco:ios_xe:*:*:*:*:*:*:*:*
cisco ios_xe < 16.3.9 cpe:2.3:o:cisco:ios_xe:*:*:*:*:*:*:*:*
cisco ios_xe >= 16.4.0, < 16.6.7 cpe:2.3:o:cisco:ios_xe:*:*:*:*:*:*:*:*
cisco ios_xe >= 16.7.0, < 16.9.4 cpe:2.3:o:cisco:ios_xe:*:*:*:*:*:*:*:*
cisco ios_xe >= 16.10.0, < 16.12.1 cpe:2.3:o:cisco:ios_xe:*:*:*:*:*:*:*:*
cisco ios < 15.6\(3\)m7 cpe:2.3:o:cisco:ios:*:*:*:*:*:*:*:*
cisco ios >= 15.7, <= 15.7\(3\)m5 cpe:2.3:o:cisco:ios:*:*:*:*:*:*:*:*
cisco ios >= 15.8, < 15.8\(3\)m3 cpe:2.3:o:cisco:ios:*:*:*:*:*:*:*:*
cisco ios >= 15.9, < 15.9\(3\)m cpe:2.3:o:cisco:ios:*:*:*:*:*:*:*:*
cisco industrial_security_appliances_3000_firmware < 1.0.05 cpe:2.3:o:cisco:industrial_security_appliances_3000_firmware:*:*:*:*:*:*:*:*
cisco integrated_services_router_4200_firmware < 1.1 cpe:2.3:o:cisco:integrated_services_router_4200_firmware:*:*:*:*:*:*:*:*
cisco integrated_services_router_4300_firmware < 1.1 cpe:2.3:o:cisco:integrated_services_router_4300_firmware:*:*:*:*:*:*:*:*
cisco integrated_services_router_4400_firmware < 1.1 cpe:2.3:o:cisco:integrated_services_router_4400_firmware:*:*:*:*:*:*:*:*
cisco ios < 15.6\(3\)m6b cpe:2.3:o:cisco:ios:*:*:*:*:*:*:*:*
cisco ios >= 15.7, <= 15.7\(3\)m4b cpe:2.3:o:cisco:ios:*:*:*:*:*:*:*:*
cisco ios >= 15.8, < 15.8\(3\)m2a cpe:2.3:o:cisco:ios:*:*:*:*:*:*:*:*
cisco asr_1000_series_firmware cpe:2.3:o:cisco:asr_1000_series_firmware:*:*:*:*:*:*:*:*
cisco asr_1001_firmware 16.0.0 cpe:2.3:o:cisco:asr_1001_firmware:16.0.0:*:*:*:*:*:*:*
cisco ios_xe < 16.2.1 cpe:2.3:o:cisco:ios_xe:*:*:*:*:*:*:*:*
cisco ios_xr 7.0.1 cpe:2.3:o:cisco:ios_xr:7.0.1:*:*:*:*:*:*:*
cisco ios_xe < 15.5\(1\)sy4 cpe:2.3:o:cisco:ios_xe:*:*:*:*:*:*:*:*
cisco ios_xe < 16.9.4 cpe:2.3:o:cisco:ios_xe:*:*:*:*:*:*:*:*
cisco ios_xe >= 16.10, < 16.12.1 cpe:2.3:o:cisco:ios_xe:*:*:*:*:*:*:*:*
cisco catalyst_9800-40_wireless_controller_firmware cpe:2.3:o:cisco:catalyst_9800-40_wireless_controller_firmware:-:*:*:*:*:*:*:*
cisco catalyst_9800-80_wireless_controller_firmware cpe:2.3:o:cisco:catalyst_9800-80_wireless_controller_firmware:-:*:*:*:*:*:*:*
cisco ic3000-k9_firmware < 1.0.2 cpe:2.3:o:cisco:ic3000-k9_firmware:*:*:*:*:*:*:*:*
cisco nx-os < 8.4.1 cpe:2.3:o:cisco:nx-os:*:*:*:*:*:*:*:*
cisco ncs2k-mr-mxp-k9_firmware < 11.1 cpe:2.3:o:cisco:ncs2k-mr-mxp-k9_firmware:*:*:*:*:*:*:*:*
cisco ios_xr 7.1.1 cpe:2.3:o:cisco:ios_xr:7.1.1:*:*:*:*:*:*:*
cisco nx-os < 9.3\(2\) cpe:2.3:o:cisco:nx-os:*:*:*:*:*:*:*:*
cisco sm-x-1t3\/e3_firmware cpe:2.3:o:cisco:sm-x-1t3\/e3_firmware:-:*:*:*:*:*:*:*
cisco encs_5100_firmware cpe:2.3:o:cisco:encs_5100_firmware:-:*:*:*:*:*:*:*
cisco encs_5400_firmware cpe:2.3:o:cisco:encs_5400_firmware:-:*:*:*:*:*:*:*

References for CVE-2019-1649

cvelogic Threat Intelligence