Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-20293— Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability

Quick assessment

Affected
Cisco Cisco Enterprise NFV Infrastructure Software
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在思科 UCS 服务器和基于 UCS 的设备的统一可扩展固件界面(UEFI)Shell 实现中存在一个漏洞,允许拥有有效凭据的已认证攻击者(其用户角色为“用户”或“管理员”),或具备物理访问权限的未认证攻击者,绕过 UEFI 安全启动验证检查,并执行未经授权的软件。 该漏洞的原因是:当设备上启用 UEFI 安全启动时,UEFI Shell 中提供了内存写入命令。攻击者可以通过在启动时选择 UEFI Shell 启动选项,并利用可用的 Shell 命令来修改 UEFI 内存变量,从而利用此漏洞。成功利用该漏洞后,攻击

CVSS 7.1 · High

Possible ATT&CK Techniques 2 AI

T1015 T1562

Affected Version Matrix 352

VendorProduct Version RangeStatus
Cisco Cisco Enterprise NFV Infrastructure Software 4.1.1 affected
3.9.1 affected
3.5.2 affected
3.12.2 affected
3.6.2 affected
3.9.2 affected
3.11.3 affected
3.11.1 affected
… +57 more rows
Cisco Cisco Unified Computing System (Managed) 4.0(1a) affected
4.1(1a) affected
4.1(1b) affected
4.0(4h) affected
4.1(1c) affected
4.0(4e) affected
4.0(4g) affected
4.0(2e) affected
… +93 more rows
Cisco Cisco Unified Computing System (Standalone) 4.0(2g) affected
3.1(2i) affected
3.1(1d) affected
4.0(4i) affected
4.1(1c) affected
4.0(2c) affected
4.0(1e) affected
4.0(2h) affected
… +172 more rows
Cisco Cisco Unified Computing System E-Series Software (UCSE) 4.11.1 affected
4.12.1 affected
4.12.2 affected
4.15.2 affected
4.15.3 affected
4.15.4 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-20293

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability
Source: CVE Program / CVE List V5
Vulnerability Description
A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UCS Servers and UCS-based appliances could allow an authenticated attacker with valid credentials for a user account with the role of user or admin or an unauthenticated attacker with physical access to an affected device to bypass UEFI Secure Boot validation checks and execute unauthorized software. This vulnerability is due to the availability of memory write commands in the UEFI Shell while UEFI Secure Boot is enabled on a device. An attacker could exploit this vulnerability by selecting the UEFI Shell boot option at boot time and using available shell commands to modify UEFI memory variables. A successful exploit could allow the attacker to manipulate the preboot environment, overwrite UEFI Secure Boot-related memory values, and execute unauthorized software on the affected device.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
暴露危险的方法或函数
Source: CVE Program / CVE List V5

Affected Products

II. Public POCs for CVE-2026-20293

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-20293

登录查看更多情报信息。

Vendor Advisories for CVE-2026-20293 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-20293

No comments yet


Leave a comment