Database/Firmware, BMC & network fabric

UEFI Secure Boot Platform Key: ~791 firmware releases across Acer, Dell, Fujitsu, Gigabyte, HP, Intel, Lenovo
Impact
~791 firmware releases across Acer, Dell, Fujitsu, Gigabyte, HP, Intel, Lenovo, Supermicro shipped with AMI's *test* Platform Key, whose private half is public on GitHub. Anyone can sign a bootloader that the platform trusts — complete Secure Boot bypass with a below-OS, reimage-surviving implant
Who can reach it
Local, or supply-chain
What to do
Requires generating and enrolling a real per-vendor Platform Key, which is a BIOS-level key-enrollment operation, not a patch. Many affected models never received a fixed firmware, so for those the only remediation is hardware replacement or accepting that Secure Boot is decorative
Fleet impact
How widespread
very common - ~900 device models across Dell, HP, Lenovo, Gigabyte, Supermicro, Intel, Fujitsu, spanning 2012-2024
Cost to remediate
firmware-flash + key re-provisioning - each node needs a genuinely secret PK enrolled and the KEK/db chain re-signed; a leaked private key cannot be patched, only rotated
Why it hits the whole fleet
The private Platform Key is public, so Secure Boot is decorative on affected nodes: anyone who can write the ESP can sign a bootkit the firmware trusts, below the OS, across the whole affected SKU population.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.