Database/Firmware, BMC & network fabric

Trend Micro Endpoint Encryption Full Disk Encryption (UEFI pre-boot): A signed pre-boot component that allows Secure
Impact
A signed pre-boot component that allows Secure Boot bypass on affected machines. Relevant to any fleet where an endpoint-security vendor's UEFI component is part of the boot chain - the security product itself becomes the way in.
Who can reach it
Local access to a machine running the affected pre-boot component.
What to do
Vendor product update plus, where the binary is revoked, a dbx update. Worth a general lesson for fleet operators: every third-party signed EFI component you allow into the boot chain is a permanent addition to your Secure Boot attack surface, and you cannot remove it later without a revocation rollout.
References
Related entries
- AMI AptioV UEFI BIOS (SPI flash access control): Improper access control in the BIOS that lets a local attacker makeCVE-2024-2315 · AMI AptioV UEFI BIOS (SPI flash access control)Medium
- Lenovo XClarity Administrator (LXCA) - single sign-on to XCC: Where LXCA acts as the single sign-on provider for XCCCVE-2024-45101 · Lenovo XClarity Administrator (LXCA) - single sign-on to XCCMedium
- Kioxia CM6 (GPK5 and earlier), PM6 (BD0D and earlier), PM7 (C40A and earlier) enterprise NVMe/SAS SSDsCVE-2024-7726 · Kioxia CM6 (GPK5 and earlier), PM6 (BD0D and earlier), PM7 (C40A and earlier) enterprise NVMe/SAS SSDs…Medium
- NVIDIA ConnectX and BlueField: a VF holder can wedge the adapter through a control register commandCVE-2025-33207 · NVIDIA ConnectX / BlueField firmware (control register interface reachable from a VF)Medium
- Intel processors, exploitable from within VMX non-root (guest) operation - INTEL-SA-01420: Shared microarchitecturalCVE-2025-35979 · Intel processors, exploitable from within VMX non-root (guest) operation - INTEL-SA-01420Medium
- IBM Server Firmware FSP: authenticated admin gets code execution via the firmware update pathCVE-2026-18681 · IBM Server Firmware (FSP firmware update process)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.