GPU VulnDB

Database/Firmware, BMC & network fabric

Cisco UCS UEFI Shell: memory write commands bypass Secure Boot validation

CVSS 7.1CVE-2026-20293Firmware, BMC & network fabriccurated

Impact

The UEFI Shell on Cisco UCS servers and UCS-based appliances exposes memory write commands even when Secure Boot is enabled. Someone who can select the UEFI Shell boot option can overwrite Secure Boot-related UEFI memory values and load unsigned software into the preboot environment, which defeats the chain of trust the rest of the host depends on. On a UCS rack or blade hosting accelerators, this is a path to persistent pre-OS code on a node that a tenant workload later runs on, and firmware-level implants survive reimaging the operating system. The record scores it 7.1 with confidentiality and integrity impact and no availability loss.

Who can reach it

An authenticated user holding a UCS account with the user or admin role, or an unauthenticated attacker with physical access to the machine, who can reach the boot menu and choose the UEFI Shell entry.

What to do

Apply the fixed BIOS/firmware release named in the Cisco advisory (cisco-sa-ucs-uefi-sb-bypass-eb6xC5GW); the record does not list version numbers, so read the advisory for the bundle that matches your UCS platform. A BIOS update means taking the node out of service, flashing, and rebooting - schedule it as a drain-and-flash window per node. Until then, restrict who holds UCS user/admin accounts and physical console access, and consider removing the UEFI Shell from the boot order where the platform allows it.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.