CVE-2026-20293
Awaiting Analysis Awaiting Analysis - Queue

UEFI Shell Memory Write Bypass in Cisco UCS Servers

Vulnerability report for CVE-2026-20293, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-08

Assigner: Cisco Systems, Inc.

Description

A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UCS Servers and UCS-based appliances could allow an authenticated attacker with valid credentials for a user account with the role of user or admin or an unauthenticated attacker with physical access to an affected device to bypass UEFI Secure Boot validation checks and execute unauthorized software. This vulnerability is due to the availability of memory write commands in the UEFI Shell while UEFI Secure Boot is enabled on a device. An attacker could exploit this vulnerability by selecting the UEFI Shell boot option at boot time and using available shell commands to modify UEFI memory variables. A successful exploit could allow the attacker to manipulate the preboot environment, overwrite UEFI Secure Boot-related memory values, and execute unauthorized software on the affected device.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-08
Generated
2026-09-09
AI Q&A
2026-09-09
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
cisco ucs_servers *
cisco ucs_based_appliances *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-749 The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows an authenticated attacker with valid credentials or an unauthenticated attacker with physical access to bypass UEFI Secure Boot checks on Cisco UCS Servers and UCS-based appliances. The issue occurs because memory write commands are available in the UEFI Shell even when Secure Boot is enabled. An attacker could exploit this by booting into the UEFI Shell and modifying memory variables to manipulate the preboot environment and execute unauthorized software.

Impact Analysis

This vulnerability could allow attackers to bypass security controls and execute unauthorized software on affected devices. For users, this means potential compromise of system integrity, unauthorized access to data, or installation of malicious firmware. Organizations may face data breaches, operational disruptions, or compliance violations due to unauthorized system modifications.

Compliance Impact

This vulnerability could lead to non-compliance with security standards like GDPR or HIPAA by enabling unauthorized access to sensitive data or system modifications. Compromised systems may fail to meet data protection requirements, resulting in legal penalties, loss of certification, or reputational damage for organizations handling regulated data.

Mitigation Strategies

Disable access to the UEFI Shell boot option on affected devices to prevent unauthorized memory modifications. Ensure UEFI Secure Boot is enabled and properly configured to block unsigned or unauthorized software execution.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-20293. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart