Database/Firmware, BMC & network fabric

Eurosoft (UK) Ltd (signed UEFI bootloader): Signed UEFI bootloader containing a shell that executes arbitrary code
CVSS 6.7CVE-2022-34303Firmware, BMC & network fabricThree more bootloaderscurated
Impact
Signed UEFI bootloader containing a shell that executes arbitrary code, bypassing Secure Boot on any machine trusting the Microsoft third-party CA.
Who can reach it
EFI System Partition write access.
What to do
dbx revocation update. Track revocation-list version per node as a fleet health metric - this class recurs roughly annually and package inventories will never show it.
References
Related entries
- Windows Boot Manager (Secure Boot bypass): The bypass the BlackLotus UEFI bootkit used in the wildCVE-2023-24932 · Windows Boot Manager (Secure Boot bypass)Medium
- NVIDIA DGX BMC (AMI-derived management controller): The DGX-1 BMC's IPMI handler allows an authorised attackerCVE-2023-25508 · NVIDIA DGX BMC (AMI-derived management controller)Medium
- CyberPower PowerPanel Enterprise DCIM: Hard-coded credentials in the DCIM platformCVE-2023-3264 · CyberPower PowerPanel Enterprise DCIMMedium
- EDK II / OVMF (UEFI Shell left enabled in downstream Ubuntu and LXD firmware builds): Not a memory-safety bugCVE-2023-48733 · EDK II / OVMF (UEFI Shell left enabled in downstream Ubuntu and LXD firmware builds)Medium
- Intel Server OpenBMC firmware (before egs-1.15-0 / bhs-0.27): An out-of-bounds read reachable by a privileged BMC userCVE-2023-49144 · Intel Server OpenBMC firmware (before egs-1.15-0 / bhs-0.27)Medium
- Micron Crucial MX500 series SSD, firmware M3CR046CVE-2024-42642 · Micron Crucial MX500 series SSD, firmware M3CR046 - buffer overflow in the drive controller reachable from host ATA…Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.