Database/Firmware, BMC & network fabric

New Horizon Datasys (signed UEFI bootloader): Signed bootloader with a built-in mechanism to bypass Secure Boot
CVSS 6.7CVE-2022-34302Firmware, BMC & network fabricThree more bootloaderscurated
Impact
Signed bootloader with a built-in mechanism to bypass Secure Boot enforcement, described by researchers as more subtle than its siblings because it disables verification without obviously tampering with the chain. Yields a bootkit that measured boot will not flag.
Who can reach it
EFI System Partition write access on the target node.
What to do
dbx revocation, delivered via firmware or OS vendor update. No package fix exists because the vulnerable artifact is a signed third-party binary.
References
Related entries
- Eurosoft (UK) Ltd (signed UEFI bootloader): Signed UEFI bootloader containing a shell that executes arbitrary codeCVE-2022-34303 · Eurosoft (UK) Ltd (signed UEFI bootloader)Medium
- Windows Boot Manager (Secure Boot bypass): The bypass the BlackLotus UEFI bootkit used in the wildCVE-2023-24932 · Windows Boot Manager (Secure Boot bypass)Medium
- NVIDIA DGX BMC (AMI-derived management controller): The DGX-1 BMC's IPMI handler allows an authorised attackerCVE-2023-25508 · NVIDIA DGX BMC (AMI-derived management controller)Medium
- CyberPower PowerPanel Enterprise DCIM: Hard-coded credentials in the DCIM platformCVE-2023-3264 · CyberPower PowerPanel Enterprise DCIMMedium
- EDK II / OVMF (UEFI Shell left enabled in downstream Ubuntu and LXD firmware builds): Not a memory-safety bugCVE-2023-48733 · EDK II / OVMF (UEFI Shell left enabled in downstream Ubuntu and LXD firmware builds)Medium
- Intel Server OpenBMC firmware (before egs-1.15-0 / bhs-0.27): An out-of-bounds read reachable by a privileged BMC userCVE-2023-49144 · Intel Server OpenBMC firmware (before egs-1.15-0 / bhs-0.27)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.