

Rewterz Threat Alert – Amavaldo – A Latin American Banking Trojan Causing Financial Loss
August 5, 2019
Rewterz Threat Advisory – Microsoft Windows PowerShell Command Execution Vulnerability
August 5, 2019
Rewterz Threat Alert – Amavaldo – A Latin American Banking Trojan Causing Financial Loss
August 5, 2019
Rewterz Threat Advisory – Microsoft Windows PowerShell Command Execution Vulnerability
August 5, 2019Severity
High
Analysis Summary
The vulnerability is due to an improper check on the area of code that manages on-premise updates to a Field Programmable Gate Array (FPGA) part of the Secure Boot hardware implementation. An attacker with elevated privileges and access to the underlying operating system that is running on the affected device could exploit this vulnerability by writing a modified firmware image to the FPGA. A successful exploit could either cause the device to become unusable (and require a hardware replacement) or allow tampering with the Secure Boot verification process, which under some circumstances may allow the attacker to install and boot a malicious software image.
Impact
Device unusable
Affected Vendors
Cisco
Remediation
Please see vendor’s advisory for the list of the affected products and more details.
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190513-secureboot