Cisco Integrated Management Controller UEFI Shell Secure Boot Bypass (cisco-sa-ucs-uefi-sb-bypass-eb6xC5GW)

high Nessus Plugin ID 348182

Synopsis

The remote device is missing a vendor-supplied security patch.

Description

According to its self-reported version, the Cisco Integrated Management Controller is affected by a vulnerability.

- A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UCS Servers and UCS-based appliances could allow an authenticated attacker with valid credentials for a user account with the role of user or admin or an unauthenticated attacker with physical access to an affected device to bypass UEFI Secure Boot validation checks and execute unauthorized software. This vulnerability is due to the availability of memory write commands in the UEFI Shell while UEFI Secure Boot is enabled on a device. An attacker could exploit this vulnerability by selecting the UEFI Shell boot option at boot time and using available shell commands to modify UEFI memory variables. A successful exploit could allow the attacker to manipulate the preboot environment, overwrite UEFI Secure Boot-related memory values, and execute unauthorized software on the affected device. (CVE-2026-20293)

Please see the included Cisco BIDs and Cisco Security Advisory for more information.

Solution

Upgrade to the fixed release listed for the affected model in the Cisco Security Advisory. See Cisco bug IDs CSCwt77804, CSCwt78022, CSCwu42927 and CSCwu42928.

See Also

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwt77804

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwt78022

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwu42927

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwu42928

http://www.nessus.org/u?584e2787

Plugin Details

Severity: High

ID: 348182

File Name: cisco-sa-ucs-uefi-sb-bypass-eb6xC5GW-cimc.nasl

Version: 1.1

Type: Combined

Family: CISCO

Published: 9/18/2026

Updated: 9/18/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.3

Percentile: 96.41

CVSS v2

Risk Factor: Medium

Base Score: 6.2

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:N

CVSS Score Source: CVE-2026-20293

CVSS v3

Risk Factor: High

Base Score: 7.1

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Vulnerability Information

CPE: cpe:/a:cisco:integrated_management_controller

Required KB Items: Host/Cisco/CIMC/version, Host/Cisco/CIMC/model

Patch Publication Date: 9/8/2026

Vulnerability Publication Date: 9/8/2026

Reference Information

CVE: CVE-2026-20293