Database/Firmware, BMC & network fabric

Eurosoft (UK) Ltd (signed UEFI bootloader): Signed UEFI bootloader containing a shell that executes arbitrary code
CVE-2022-34303Firmware, BMC & network fabricThree more bootloaderscurated
Impact
Signed UEFI bootloader containing a shell that executes arbitrary code, bypassing Secure Boot on any machine trusting the Microsoft third-party CA.
Who can reach it
EFI System Partition write access.
What to do
dbx revocation update. Track revocation-list version per node as a fleet health metric - this class recurs roughly annually and package inventories will never show it.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.