Cisco UCS Manager UEFI Shell Secure Boot Bypass (cisco-sa-ucs-uefi-sb-bypass-eb6xC5GW)

high Nessus Plugin ID 348181

Synopsis

The remote device is missing a vendor-supplied security patch.

Description

According to its self-reported version, Cisco UCS Manager Software is affected by a vulnerability.

- A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UCS Servers and UCS-based appliances could allow an authenticated attacker with valid credentials for a user account with the role of user or admin or an unauthenticated attacker with physical access to an affected device to bypass UEFI Secure Boot validation checks and execute unauthorized software. This vulnerability is due to the availability of memory write commands in the UEFI Shell while UEFI Secure Boot is enabled on a device. An attacker could exploit this vulnerability by selecting the UEFI Shell boot option at boot time and using available shell commands to modify UEFI memory variables. A successful exploit could allow the attacker to manipulate the preboot environment, overwrite UEFI Secure Boot-related memory values, and execute unauthorized software on the affected device. (CVE-2026-20293)

Please see the included Cisco BID and Cisco Security Advisory for more information.

Solution

Upgrade to the relevant fixed version referenced in Cisco bug ID CSCwt77804.

See Also

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwt77804

http://www.nessus.org/u?584e2787

Plugin Details

Severity: High

ID: 348181

File Name: cisco-sa-ucs-uefi-sb-bypass-eb6xC5GW-ucs.nasl

Version: 1.1

Type: Remote

Family: CISCO

Published: 9/18/2026

Updated: 9/18/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.3

Percentile: 96.41

CVSS v2

Risk Factor: Medium

Base Score: 6.2

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:N

CVSS Score Source: CVE-2026-20293

CVSS v3

Risk Factor: High

Base Score: 7.1

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Vulnerability Information

CPE: cpe:/a:cisco:unified_computing_system

Required KB Items: installed_sw/cisco_ucs_manager

Patch Publication Date: 9/8/2026

Vulnerability Publication Date: 9/8/2026

Reference Information

CVE: CVE-2026-20293

CWE: 749

CISCO-SA: cisco-sa-ucs-uefi-sb-bypass-eb6xC5GW

IAVA: 2026-A-1027

CISCO-BUG-ID: CSCwt77804