CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

[UPDATE] [mittel] Insyde UEFI Firmware und Cisco UCS (UEFI Shell Secure Boot): Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen

mediumCVE-2026-20293CVE-2026-6485
Ein Angreifer kann eine Schwachstelle in Insyde UEFI Firmware und Cisco Unified Computing System (UCS) ausnutzen, um den UEFI-Secure-Boot zu umgehen, die Pre-Boot-Umgebung zu manipulieren und beliebigen Code auszuführen.

Details

Source
CERT-Bund (BSI) Security Advisories (DE · national-cert · site)
Severity
medium
Published
2026-09-10
Exploitation
Not in CISA KEV at last sync

Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3240

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-20293coverage & exploitation statusNVD · CVE.org
CVE-2026-6485coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for Insyde UEFI Firmware

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from CERT-Bund (BSI) Security Advisories