Database/Firmware, BMC & network fabric

Cisco UCS UEFI Shell: memory write commands bypass Secure Boot validation
Impact
The UEFI Shell on Cisco UCS servers and UCS-based appliances exposes memory write commands even when Secure Boot is enabled. Someone who can select the UEFI Shell boot option can overwrite Secure Boot-related UEFI memory values and load unsigned software into the preboot environment, which defeats the chain of trust the rest of the host depends on. On a UCS rack or blade hosting accelerators, this is a path to persistent pre-OS code on a node that a tenant workload later runs on, and firmware-level implants survive reimaging the operating system. The record scores it 7.1 with confidentiality and integrity impact and no availability loss.
Who can reach it
An authenticated user holding a UCS account with the user or admin role, or an unauthenticated attacker with physical access to the machine, who can reach the boot menu and choose the UEFI Shell entry.
What to do
Apply the fixed BIOS/firmware release named in the Cisco advisory (cisco-sa-ucs-uefi-sb-bypass-eb6xC5GW); the record does not list version numbers, so read the advisory for the bundle that matches your UCS platform. A BIOS update means taking the node out of service, flashing, and rebooting - schedule it as a drain-and-flash window per node. Until then, restrict who holds UCS user/admin accounts and physical console access, and consider removing the UEFI Shell from the boot order where the platform allows it.
References
Related entries
- Linux bnxt_en driver (DBG_BUF_PRODUCER async event handler): The async-event handler indexes a fixed arrayCVE-2026-31395 · Linux bnxt_en driver (DBG_BUF_PRODUCER async event handler)High
- Junos OS MX Series PFE: micro-BFD flapping starves PFEMAN until the watchdog crashes and restarts the FPCCVE-2026-33800 · Juniper Junos OS on MX Series (Packet Forwarding Engine, PFEMAN micro-BFD event processing)High
- Dell iDRAC10 (credential handling, race condition): A race in iDRAC10's credential handling leaves secretsCVE-2026-35155 · Dell iDRAC10 (credential handling, race condition)High
- Linux kernel InfiniBand core (ib_uverbs post_send): ib_uverbs_post_send() takes the work-queue-entry size straightCVE-2026-45856 · Linux kernel InfiniBand core (ib_uverbs post_send)High
- Linux kernel RDMA core (UVERBS_ATTR_ALLOC_DMAH_CPU_ID, DMA handle allocation): The cpu_id a tenant passes whenCVE-2026-53187 · Linux kernel RDMA core (UVERBS_ATTR_ALLOC_DMAH_CPU_ID, DMA handle allocation)High
- Dell OpenManage Enterprise: SQL injection reachable by a low-privileged remote userCVE-2026-56088 · Dell OpenManage Enterprise (web console, SQL injection)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.