Database/Firmware, BMC & network fabric

Windows Boot Manager (Secure Boot bypass): The bypass the BlackLotus UEFI bootkit used in the wild
Impact
The bypass the BlackLotus UEFI bootkit used in the wild. An attacker with admin or physical access installs a bootkit that survives OS reinstall and disk replacement, disables Secure Boot enforcement from inside the boot chain, and hides from every in-OS security agent. On a mixed Windows/Linux estate this also poisons attestation for anything downstream.
Who can reach it
Local administrator or physical access - which on bare metal means any tenant that rented the node, and on a colo floor means anyone with remote-hands.
What to do
The most operationally painful entry in this cluster. The security update alone does nothing: Microsoft shipped it behind a manual, multi-stage opt-in requiring boot manager updates, revocation of the old boot manager, and a UEFI CA/dbx update, staged over roughly two years precisely because enabling revocation early bricks machines that still boot old media. Budget for a phased rollout with per-node verification, keep known-good recovery media that is still trusted, and expect to touch firmware settings on some boards. Not a patch-and-forget.
References
Related entries
- NVIDIA DGX BMC (AMI-derived management controller): The DGX-1 BMC's IPMI handler allows an authorised attackerCVE-2023-25508 · NVIDIA DGX BMC (AMI-derived management controller)Medium
- CyberPower PowerPanel Enterprise DCIM: Hard-coded credentials in the DCIM platformCVE-2023-3264 · CyberPower PowerPanel Enterprise DCIMMedium
- EDK II / OVMF (UEFI Shell left enabled in downstream Ubuntu and LXD firmware builds): Not a memory-safety bugCVE-2023-48733 · EDK II / OVMF (UEFI Shell left enabled in downstream Ubuntu and LXD firmware builds)Medium
- Intel Server OpenBMC firmware (before egs-1.15-0 / bhs-0.27): An out-of-bounds read reachable by a privileged BMC userCVE-2023-49144 · Intel Server OpenBMC firmware (before egs-1.15-0 / bhs-0.27)Medium
- Micron Crucial MX500 series SSD, firmware M3CR046CVE-2024-42642 · Micron Crucial MX500 series SSD, firmware M3CR046 - buffer overflow in the drive controller reachable from host ATA…Medium
- Lenovo ThinkSystem UEFI/BIOS (SMM callout): A System Management Mode callout vulnerability in ThinkSystem UEFICVE-2024-45105 · Lenovo ThinkSystem UEFI/BIOS (SMM callout)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.