Database/Firmware, BMC & network fabric
Cisco NX-OS (bootloader / image signature verification): Secure boot on the switch is defeatable: an attacker
Impact
Secure boot on the switch is defeatable: an attacker with physical access or admin credentials can make a Nexus load an unsigned NX-OS image. That is how a fabric compromise becomes permanent — a modified image keeps root across reloads and reflashes, and nothing in your config management will notice. Affects Nexus 3000/7000/9000, MDS 9000 and UCS 6400/6500 fabric interconnects, so it covers both the Ethernet and the storage fabric.
Who can reach it
Physical access to the switch (console/bootloader prompt) or an existing administrative account. Realistic threat model for colocation, shared cages, and any switch that has passed through a supply chain or an RMA.
What to do
BIOS update on both the primary and the alternate BIOS bank — either through install all with a fixed NX-OS release or Cisco's release-independent BIOS upgrade script. This is a firmware flash, needs a reload, and must be applied per-device; you cannot fix it with config. Pair it with physical access control on the console ports.
References
Related entries
- AMI AptioV UEFI BIOS (SPI flash integrity verification): An actor with physical access can modify the SPI flashCVE-2024-33660 · AMI AptioV UEFI BIOS (SPI flash integrity verification)Medium
- shim (MZ/PE header parser): Out-of-bounds read parsing MZ binariesCVE-2023-40551 · shim (MZ/PE header parser)Medium
- Solidigm DC SSDs (D3-S4510/S4520/S4610/S4620, D5-P5316, D7-P5520/P5620, DC S4500/S4600)CVE-2024-47973 · Solidigm DC SSDs (D3-S4510/S4520/S4610/S4620, D5-P5316, D7-P5520/P5620, DC S4500/S4600) - over-provisioned NAND not…Medium
- Arm Neoverse V2 / V3 / V3AE, Cortex-X3 / X4 / X925, C1-seriesCVE-2024-7881 · Arm Neoverse V2 / V3 / V3AE, Cortex-X3 / X4 / X925, C1-series; mitigated in Trusted Firmware-A v2.2-v2.12 and LTS…Medium
- Junos Space: stored XSS in management UI pages lets an attacker run actions as a logged-in administratorCVE-2025-59990 · Juniper Junos Space (template creation and report generation pages)Medium
- NVIDIA UFM Enterprise: hard-coded key in session management allows information disclosure and privilege escalationCVE-2026-24166 · NVIDIA UFM Enterprise (session management, hard-coded cryptographic key)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.