GPU VulnDB

Database/Firmware, BMC & network fabric

InsydeH2O UEFI firmware: embedded UEFI Shell can be used to bypass Secure Boot

CVSS 8.2CVE-2026-6485Firmware, BMC & network fabriccurated

Impact

The UEFI Shell built into affected InsydeH2O firmware can be driven, by shell commands or a startup script, to load code that Secure Boot is supposed to reject. Secure Boot is the control that makes a node's boot chain worth trusting, so losing it means a compromised or malicious bootloader or kernel can be planted where the running OS cannot see it. Insyde scores this with a scope change and full confidentiality, integrity and availability impact from local privileged access. On a node whose measured-boot or attestation posture is used to decide whether it is allowed to hold sensitive workloads, this quietly invalidates that decision. The record does not name affected firmware versions or the shipping OEMs.

Who can reach it

Local, high-privilege access (CVSS AV:L/PR:H): someone who can already reach the firmware setup or place a startup script on an EFI volume - a host-root attacker, or anyone with physical or out-of-band console access. Not reachable by an unprivileged tenant workload.

What to do

Apply the firmware update your OEM ships for Insyde SA-2026004; there is no OS-level patch. That is a per-node maintenance window: drain the node, flash, reboot. Until a build exists for a given platform, reduce reach by removing the embedded Shell where the firmware allows it, setting a firmware administrator password, and restricting who can reach the console or the out-of-band update path.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.