Database/Firmware, BMC & network fabric

Signed third-party UEFI application (Howyar Reloader and OEM rebrands): A Microsoft-signed UEFI recovery application
Impact
A Microsoft-signed UEFI recovery application loads an unsigned binary from a hardcoded path using its own loader instead of the firmware's verified LoadImage. Anyone holding a copy of that signed application can drop it on any Secure Boot machine that trusts the Microsoft third-party CA and boot arbitrary pre-OS code - the vulnerable system does not need the vendor's product installed. That is a universal, portable Secure Boot bypass usable to plant a bootkit on a rented GPU node.
Who can reach it
Write access to the EFI System Partition - local admin/root, prior bare-metal tenant, or BMC virtual media. No relationship to whether you use the affected recovery software.
What to do
Apply the January 2025 UEFI revocation list (dbx) update that revokes the affected binaries - this is a firmware-level revocation, not a package update, so it lands via Windows Update, fwupd/LVFS, or an OEM BIOS update depending on the platform. Verify the revocation actually took on each node; dbx pushes silently no-op on some boards. Also audit the ESP for stray signed EFI applications you never installed.
References
Related entries
- Insyde InsydeH2O (H19Int15CallbackSmm, combined DXE/SMM driver): An unchecked output buffer in a combined DXE/SMMCVE-2025-10451 · Insyde InsydeH2O (H19Int15CallbackSmm, combined DXE/SMM driver)High
- Intel Server Firmware Update Utility (SysFwUpdt) and Server Configuration Utility before version 16.0.12: ImproperCVE-2025-25210 · Intel Server Firmware Update Utility (SysFwUpdt) and Server Configuration Utility before version 16.0.12High
- AMI AptioV UEFI BIOS (SMM): A write-what-where primitive plus an information leak in System Management ModeCVE-2025-33045 · AMI AptioV UEFI BIOS (SMM)High
- Broadcom NetXtreme-E network adapter firmware: A high-severity flaw in the firmware of Broadcom NetXtreme-E adaptersCVE-2025-56547 · Broadcom NetXtreme-E network adapter firmwareHigh
- IBM Power Systems Firmware: BMC/FSP-to-host interface allows arbitrary code execution on the host systemCVE-2026-16930 · IBM Power Systems Firmware (BMC/FSP-to-host interface)High
- IBM Power Systems Firmware: BMC/FSP can read and write arbitrary host system memoryCVE-2026-16933 · IBM Power Systems Firmware (BMC/FSP-to-host memory interface)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.