Cisco Security Advisory
Follow
Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability
A vulnerability exists in the UEFI Shell implementation of Cisco UCS Servers and related appliances. This flaw allows an attacker to bypass UEFI Secure Boot validation. The issue stems from the presence of memory write commands within the UEFI Shell. When UEFI Secure Boot is active, these commands can be exploited. An authenticated attacker with user or admin privileges can leverage this. Alternatively, an unauthenticated attacker with physical access can exploit it. The attacker would select the UEFI Shell boot option during startup. They would then use shell commands to alter UEFI memory variables. This manipulation can overwrite Secure Boot related memory values. Ultimately, the attacker can execute unauthorized software on the device. Cisco has issued software updates to fix this vulnerability. There are no alternative workarounds available.