Description
A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UCS Servers and UCS-based appliances could allow an authenticated attacker with valid credentials for a user account with the role of user or admin or an unauthenticated attacker with physical access to an affected device to bypass UEFI Secure Boot validation checks and execute unauthorized software.

This vulnerability is due to the availability of memory write commands in the UEFI Shell while UEFI Secure Boot is enabled on a device. An attacker could exploit this vulnerability by selecting the UEFI Shell boot option at boot time and using available shell commands to modify UEFI memory variables. A successful exploit could allow the attacker to manipulate the preboot environment, overwrite UEFI Secure Boot-related memory values, and execute unauthorized software on the affected device.
Published: 2026-09-08
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from the availability of memory write commands in the UEFI Shell while Secure Boot is enabled. An attacker can select the UEFI Shell boot option at startup and use shell commands to write to UEFI memory variables. The result is a bypass of Secure Boot validation, allowing the attacker to modify the preboot environment, overwrite Secure Boot‑related memory values, and execute unauthorized firmware or code. This flaw directly compromises the integrity of the system’s pre‑boot environment, potentially enabling persistent root-level malware.

Affected Systems

The affected products are Cisco Enterprise NFV Infrastructure Software, Cisco Unified Computing System (Managed), Cisco Unified Computing System (Standalone), and Cisco Unified Computing System E‑Series Software (UCSE). All versions of these UEFI firmware implementations that include the vulnerable Shell interface are impacted; specific version ranges are not listed in the data.

Risk and Exploitability

The CVSS score of 7.1 indicates a moderate to high severity. The EPSS score is not available, so the current probability of exploitation cannot be quantified from the public data, and the vulnerability is not listed in CISA's KEV catalog. The likely attack vector requires either authenticated access with user or admin credentials or physical access to the device at boot time. The flaw permits privileged attackers to modify critical firmware variables, and once bypassed, the attacker can run arbitrary code before the operating system loads.

Generated by OpenCVE AI on September 8, 2026 at 18:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and install the latest Cisco UCS firmware update that removes memory write commands from the UEFI Shell while Secure Boot is enabled.
  • Verify that UEFI Secure Boot remains enabled in the firmware configuration, and disable the UEFI Shell boot option if not needed.
  • Implement strict physical security controls and limit console access to authorized personnel. For systems without an update, change administrative passwords and enforce least‑privilege principles to reduce the risk from authenticated attackers.

Generated by OpenCVE AI on September 8, 2026 at 18:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UCS Servers and UCS-based appliances could allow an authenticated attacker with valid credentials for a user account with the role of user or admin or an unauthenticated attacker with physical access to an affected device to bypass UEFI Secure Boot validation checks and execute unauthorized software. This vulnerability is due to the availability of memory write commands in the UEFI Shell while UEFI Secure Boot is enabled on a device. An attacker could exploit this vulnerability by selecting the UEFI Shell boot option at boot time and using available shell commands to modify UEFI memory variables. A successful exploit could allow the attacker to manipulate the preboot environment, overwrite UEFI Secure Boot-related memory values, and execute unauthorized software on the affected device.
Title Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability
Weaknesses CWE-749
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-08T16:04:40.874Z

Reserved: 2025-10-08T11:59:15.405Z

Link: CVE-2026-20293

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T17:17:34.047

Modified: 2026-09-08T18:35:10.323

Link: CVE-2026-20293

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T18:45:05Z

Weaknesses
  • CWE-749

    Exposed Dangerous Method or Function