Database/Firmware, BMC & network fabric

CryptoPro Secure Disk (signed UEFI bootloader): A Microsoft-signed bootloader that can be made to execute arbitrary
Impact
A Microsoft-signed bootloader that can be made to execute arbitrary pre-boot code. Same portable-bypass shape as the Howyar case: the attacker brings the signed binary with them, so a fleet that never deployed this product is still exploitable simply because the firmware trusts the signature.
Who can reach it
Write access to the EFI System Partition on the target node.
What to do
dbx revocation update pushed to every node via firmware update or OS vendor channel - not a package upgrade. Verify the dbx entry is present afterwards; revocation is the only fix because the vulnerable binary is signed and portable.
References
Related entries
- New Horizon Datasys (signed UEFI bootloader): Signed bootloader with a built-in mechanism to bypass Secure BootCVE-2022-34302 · New Horizon Datasys (signed UEFI bootloader)Medium
- Eurosoft (UK) Ltd (signed UEFI bootloader): Signed UEFI bootloader containing a shell that executes arbitrary codeCVE-2022-34303 · Eurosoft (UK) Ltd (signed UEFI bootloader)Medium
- Windows Boot Manager (Secure Boot bypass): The bypass the BlackLotus UEFI bootkit used in the wildCVE-2023-24932 · Windows Boot Manager (Secure Boot bypass)Medium
- NVIDIA DGX BMC (AMI-derived management controller): The DGX-1 BMC's IPMI handler allows an authorised attackerCVE-2023-25508 · NVIDIA DGX BMC (AMI-derived management controller)Medium
- CyberPower PowerPanel Enterprise DCIM: Hard-coded credentials in the DCIM platformCVE-2023-3264 · CyberPower PowerPanel Enterprise DCIMMedium
- EDK II / OVMF (UEFI Shell left enabled in downstream Ubuntu and LXD firmware builds): Not a memory-safety bugCVE-2023-48733 · EDK II / OVMF (UEFI Shell left enabled in downstream Ubuntu and LXD firmware builds)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.