Database/Firmware, BMC & network fabric

ArubaOS GRUB2 implementation (secure boot): Two flaws in ArubaOS's GRUB2 implementation allow secure boot
Impact
Two flaws in ArubaOS's GRUB2 implementation allow secure boot to be bypassed, leading to remote compromise. Secure boot on a network device is the control that stops a compromise from becoming permanent; bypassing it means an attacker's image survives reimaging and firmware updates. Same structural problem as the Cisco NX-OS image-verification bypass, on a different vendor.
Who can reach it
An attacker able to influence the boot chain — via administrative access or the documented remote path.
What to do
ArubaOS upgrade plus reload; this is a bootloader-level fix so it must be applied per device and cannot be worked around in config. Treat any device suspected of pre-patch compromise as needing replacement or a verified out-of-band reflash rather than an in-place upgrade.
References
Related entries
- Inspur NF5266M5 through firmware 3.21.2 and other Inspur M5-generation servers: An attacker with administrative reachCVE-2020-26122 · Inspur NF5266M5 through firmware 3.21.2 and other Inspur M5-generation serversHigh
- AMD SEV / SEV-ES - guest address space rearrangement undetected by attestation: A malicious hypervisor can rearrangeCVE-2021-26311 · AMD SEV / SEV-ES - guest address space rearrangement undetected by attestationHigh
- Intel TXT SINIT Authenticated Code Module for some Intel processors: Improper initialization in the SINIT ACMCVE-2022-30704 · Intel TXT SINIT Authenticated Code Module for some Intel processorsHigh
- Intel Xeon memory controller configuration (with SGX): Memory controller configuration registers are left withCVE-2022-33196 · Intel Xeon memory controller configuration (with SGX)High
- Intel Xeon processors (SGX/TDX error injection): Unauthorised error injection against SGX or TDX on affected Xeon partsCVE-2022-41804 · Intel Xeon processors (SGX/TDX error injection)High
- NVIDIA DGX BMC (AMI-derived management controller): The BMC's SPX REST API lets an authorised attacker read and writeCVE-2022-42278 · NVIDIA DGX BMC (AMI-derived management controller)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.