Database/Firmware, BMC & network fabric

InsydeH2O UEFI firmware: embedded UEFI Shell can be used to bypass Secure Boot
Impact
The UEFI Shell built into affected InsydeH2O firmware can be driven, by shell commands or a startup script, to load code that Secure Boot is supposed to reject. Secure Boot is the control that makes a node's boot chain worth trusting, so losing it means a compromised or malicious bootloader or kernel can be planted where the running OS cannot see it. Insyde scores this with a scope change and full confidentiality, integrity and availability impact from local privileged access. On a node whose measured-boot or attestation posture is used to decide whether it is allowed to hold sensitive workloads, this quietly invalidates that decision. The record does not name affected firmware versions or the shipping OEMs.
Who can reach it
Local, high-privilege access (CVSS AV:L/PR:H): someone who can already reach the firmware setup or place a startup script on an EFI volume - a host-root attacker, or anyone with physical or out-of-band console access. Not reachable by an unprivileged tenant workload.
What to do
Apply the firmware update your OEM ships for Insyde SA-2026004; there is no OS-level patch. That is a per-node maintenance window: drain the node, flash, reboot. Until a build exists for a given platform, reduce reach by removing the embedded Shell where the firmware allows it, setting a firmware administrator password, and restricting who can reach the console or the out-of-band update path.
References
Related entries
- Supermicro IPMI BMC firmware: Every affected BMC shares one TLS private key and one SSH host key, baked into theCVE-2013-3619 · Supermicro IPMI BMC firmwareHigh
- Dell iDRAC6/iDRAC7 IPMI 1.5 session handling: IPMI 1.5 session IDs are handed out incrementally from a small pool, soCVE-2014-8272 · Dell iDRAC6/iDRAC7 IPMI 1.5 session handlingHigh
- Dell iDRAC9: Stack overflow overwriting iDRAC configuration via oversized payloadsCVE-2021-21540 · Dell iDRAC9High
- GRUB2 (net/ip IPv4 reassembly): Integer underflow in grub_net_recv_ip4_packets from a crafted IP packetCVE-2022-28733 · GRUB2 (net/ip IPv4 reassembly)High
- ATEN PE8108 switched PDU: A restricted (non-admin) user account on the PDU's web interface can control outletsCVE-2023-25409 · ATEN PE8108 switched PDUHigh
- AMI MegaRAC SPx (IPMI handler): Buffer overflow in the BMC's IPMI message handler leading to code executionCVE-2023-34336 · AMI MegaRAC SPx (IPMI handler)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.