ZeroHour
Cisco Security Advisoriespublished ()ingested

Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability

lowAdvisoryimportance 20
AI summary · glm-5.3-flash

Cisco disclosed a UEFI Secure Boot bypass in UCS servers and UCS-based appliances letting authenticated or physically present attackers execute unauthorized software.

Cisco published an advisory for a vulnerability in the UEFI Shell implementation of UCS servers and UCS-based appliances. Memory write commands remain available in the UEFI Shell while Secure Boot is enabled, allowing an attacker to modify UEFI memory and bypass validation checks to run unauthorized software. Exploitation requires either valid credentials for a user or admin account, or unauthenticated physical access to select the UEFI Shell boot option at boot time. The issue affects firmware boot integrity rather than the running operating system.

  • UEFI Shell memory write commands remain available even when Secure Boot is enabled
  • Exploitation requires authenticated shell access or physical access at boot time
  • Impact is limited to bypassing Secure Boot validation to execute unauthorized software
VendorsCisco
ProductsCisco UCS
Full article

A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UCS Servers and UCS-based appliances could allow an authenticated attacker with valid credentials for a user account with the role of user or admin or an unauthenticated attacker with physical access to an affected device to bypass UEFI Secure Boot validation checks and execute unauthorized software. This vulnerability is due to the availability of memory write commands in the UEFI Shell while UEFI Secure Boot is enabled on a device. An attacker could exploit this vulnerability by selecting the UEFI Shell boot option at boot time and using available shell commands to modify UEFI memory…

This source does not provide full text. Read it at sec.cloudapps.cisco.com.