Executive brief
Cisco UCS Servers and UCS-based appliances contain a vulnerability in their UEFI firmware shell that allows attackers to bypass Secure Boot protections and execute unauthorized code during boot. An attacker with physical access to a device's keyboard/video console, or with valid user/admin credentials, can use shell commands to modify firmware memory and disable security checks, potentially installing malicious software that persists across reboots.
Technical details
This vulnerability stems from the availability of memory-write commands in the UEFI Shell (CWE-749) when UEFI Secure Boot is enabled. The root cause is insufficient isolation between the interactive shell environment and protected firmware state. An attacker can select the UEFI Shell boot option and use shell commands to modify UEFI memory variables, specifically overwriting Secure Boot-related values. Attack vectors include physical access to keyboard/video/mouse (KVM) for unauthenticated users, or remote/local access for authenticated users with user or admin role. Successful exploitation allows complete bypass of firmware signature validation and execution of arbitrary code in the preboot environment. Cisco's fix removes memory-modification shell commands when Secure Boot is enabled; patches are available for affected BIOS versions.
Affected products
- Cisco UCS B-Series Blade Servers
- Cisco UCS C-Series Rack Servers
- Cisco UCS C845A M8 Rack Server
- Cisco UCS C885A M8 Rack Server
- Cisco UCS C880A M8 Rack Server
- Cisco UCS E-Series M3 Servers
- Cisco UCS E-Series M6 Servers
- Cisco UCS S-Series Storage Servers
- Cisco UCS X-Series Modular System
- Cisco 5000 Series Enterprise Network Compute Systems
- Cisco Unified Edge
- Cisco Application Policy Infrastructure Controller
- Cisco Telemetry Broker
- Cisco HyperFlex Edge Nodes
- Cisco HyperFlex Nodes
- Cisco IEC6400 Edge Compute Appliances
- Cisco IOS XRv 9000 M7
- Cisco Nexus Dashboard
- Cisco Secure Email Gateway
- Cisco Secure Email and Web Manager
- Cisco Secure Endpoint Private Cloud
- Cisco Secure Firewall Management Center
- Cisco Secure Malware Analytics
- Cisco Secure Network Analytics
- Cisco Secure Network Server
- Cisco Secure Web Appliances
Timeline
- 2026-09-08: disclosed
- 2026-09-08: advisory: Cisco Security Advisory published