ZeroHour

CVE-2026-20293

large

Secure Boot Bypass via UEFI Shell in Cisco UCS Servers and UCS-based Appliances

CVSS 3.1
7.1 high
EPSS
<1%p3
Published
()
Modified
AI analysis

CVE-2026-20293 is a flaw in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UCS Servers and UCS-based appliances that lets an attacker bypass UEFI Secure Boot validation and run unauthorized software. It is triggered because memory-write commands remain available in the UEFI Shell even while Secure Boot is enabled: an attacker selects the UEFI Shell boot option at boot time and uses shell commands to modify UEFI memory variables and overwrite Secure Boot-related memory values. A successful exploit manipulates the preboot environment and allows execution of untrusted software that would normally be rejected by Secure Boot. Exploitation requires either physical access (no credentials needed) or valid credentials for an account with the user or admin role on the affected system, so practical exposure is limited to systems where an attacker has local access. No exploitation in the wild, public proof-of-concept, or KEV listing is known, and EPSS puts 30-day exploitation probability at about 0.1%.

What to do: Upgrade UCS server and appliance firmware to the fixed releases listed in the Cisco PSIRT advisory for CVE-2026-20293 (specific versions are not included in the data provided). Until patched, restrict physical access to UCS hosts, limit local user/admin credentials, and restrict or remove the UEFI Shell option from the boot menu so it cannot be selected at boot time. Because exploitation requires local access and there is no known in-the-wild exploitation, prioritize systems that are physically accessible or widely shared (e.g., branch or lab locations).

Affected
Cisco UCS Servers (UEFI Shell implementation)
Cisco UCS-based appliances (UEFI Shell implementation)
Estimated exposure
largeon the order of hundreds of thousands of deployed UCS servers and UCS-based appliances worldwide (estimated from Cisco's large enterprise server installed base) — Cisco UCS is a mainstream enterprise x86 server and appliance line with a large installed data-center footprint, and the flaw affects the embedded UEFI Shell across affected platforms; no public install counts were provided, so this is an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UCS Servers and UCS-based appliances could allow an authenticated attacker with valid credentials for a user account with the role of user or admin or an unauthenticated attacker with physical access to an affected device to bypass UEFI Secure Boot validation checks and execute unauthorized software. This vulnerability is due to the availability of memory write commands in the UEFI Shell while UEFI Secure Boot is enabled on a device. An attacker could exploit this vulnerability by selecting the UEFI Shell boot option at boot time and using available shell commands to modify UEFI memory variables. A successful exploit could allow the attacker to manipulate the preboot environment, overwrite UEFI Secure Boot-related memory values, and execute unauthorized software on the affected device.

Weakness
CWE-749
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

In the news

VU#718077: UEFI Shell module embedded in SPI Flash can be used to bypass Secure Boot

CERT/CC details VU#718077: UEFI Shell embedded in SPI flash lets attackers bypass Secure Boot and execute pre-boot code; patches issued.

CERT/CC's VU#718077, reported by Eclypsium researcher Stas Lyakhov, describes how a UEFI Shell embedded in SPI flash can be abused by attackers who can modify UEFI boot configuration, creating multiple boot entries that bypass controls preventing the Shell from launching under Secure Boot. The Shell's dmem and mm commands allow arbitrary physical memory read/write, letting attackers overwrite Secure Boot values and execute unauthorized pre-boot code that can persist across reboots and OS reinstalls while degrading EDR effectiveness. AMI confirmed its Aptio UEFI BDS module is affected (CVE-2026-33197), and Cisco published an advisory for a variation affecting UCS Servers and UCS-based appliances (CVE-2026-20293). Firmware patches are being rolled out through OEM and IBV BIOS build pipelines.