---
id: CVE-2026-20293
title: >-
  A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell
  implementation of Cisco UCS Servers and UCS-based appliances could allow an
  authenticated attacker with valid credentials for a user account with the role
  of user …
summary: >-
  A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell
  implementation of Cisco UCS Servers and UCS-based appliances could allow an
  authenticated attacker with valid credentials for a user account with the role
  of user …
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-749
vendor: Cisco
product: Cisco Enterprise NFV Infrastructure Software
affected:
  - enterprise_nfv_infrastructure_software 4.1.1
  - enterprise_nfv_infrastructure_software 3.9.1
  - enterprise_nfv_infrastructure_software 3.5.2
  - enterprise_nfv_infrastructure_software 3.12.2
  - enterprise_nfv_infrastructure_software 3.6.2
  - enterprise_nfv_infrastructure_software 3.9.2
  - enterprise_nfv_infrastructure_software 3.11.3
  - enterprise_nfv_infrastructure_software 3.11.1
  - enterprise_nfv_infrastructure_software 3.5.1
  - enterprise_nfv_infrastructure_software 3.3.1
  - enterprise_nfv_infrastructure_software 3.10.2
  - enterprise_nfv_infrastructure_software 3.12.1b
  - enterprise_nfv_infrastructure_software 3.4.1
  - enterprise_nfv_infrastructure_software 3.12.1a
  - enterprise_nfv_infrastructure_software 3.6.3
  - enterprise_nfv_infrastructure_software 3.8.1
  - enterprise_nfv_infrastructure_software 3.11.2
  - enterprise_nfv_infrastructure_software 3.12.1
  - enterprise_nfv_infrastructure_software 3.12.3
  - enterprise_nfv_infrastructure_software 3.10.1
  - enterprise_nfv_infrastructure_software 3.6.1
  - enterprise_nfv_infrastructure_software 3.10.3
  - enterprise_nfv_infrastructure_software 3.7.1
  - enterprise_nfv_infrastructure_software 4.1.2
  - enterprise_nfv_infrastructure_software 4.2.1
  - enterprise_nfv_infrastructure_software 4.2.2
  - enterprise_nfv_infrastructure_software 4.4.1
  - enterprise_nfv_infrastructure_software 4.4.2
  - enterprise_nfv_infrastructure_software 4.5.1
  - enterprise_nfv_infrastructure_software 4.4.3
  - enterprise_nfv_infrastructure_software 4.6.1
  - enterprise_nfv_infrastructure_software 4.7.1
  - enterprise_nfv_infrastructure_software 4.6.2-FC2
  - enterprise_nfv_infrastructure_software 4.6.2
  - enterprise_nfv_infrastructure_software 4.8.1
  - enterprise_nfv_infrastructure_software 4.8.2
  - enterprise_nfv_infrastructure_software 4.9.1
  - enterprise_nfv_infrastructure_software 4.6.3
  - enterprise_nfv_infrastructure_software 4.9.2
  - enterprise_nfv_infrastructure_software 4.10.1
  - enterprise_nfv_infrastructure_software 4.9.3
  - enterprise_nfv_infrastructure_software 4.11.1
  - enterprise_nfv_infrastructure_software 4.9.4
  - enterprise_nfv_infrastructure_software 4.12.1
  - enterprise_nfv_infrastructure_software 4.6.4
  - enterprise_nfv_infrastructure_software 4.12.2
  - enterprise_nfv_infrastructure_software 4.13.1
  - enterprise_nfv_infrastructure_software 4.9.5
  - enterprise_nfv_infrastructure_software 4.12.3
  - enterprise_nfv_infrastructure_software 4.14.1
published: '2026-09-08'
updated: '2026-09-11'
sourceUpdated: '2026-09-11T14:17:25.820'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-20293'
references:
  - url: >-
      https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ucs-uefi-sb-bypass-eb6xC5GW
    label: psirt@cisco.com
  - url: 'https://software.cisco.com'
tags:
  - nvd
  - cve.org
  - csaf
  - vendor-advisory
  - cisco
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-11T13:32:52.855324Z'
epss: 0.00132
epssPercentile: 0.03128
ingestedAt: '2026-09-08T17:06:31.935Z'
---

## Overview

A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UCS Servers and UCS-based appliances could allow an authenticated attacker with valid credentials for a user account with the role of user or admin&nbsp;or an unauthenticated attacker with physical access to an affected device to bypass UEFI Secure Boot validation checks and execute unauthorized software.

This vulnerability is due to the availability of memory write commands in the UEFI Shell while UEFI Secure Boot is enabled on a device. An attacker could exploit this vulnerability by selecting the UEFI Shell boot option at boot time and using available shell commands to modify UEFI memory variables. A successful exploit could allow the attacker to manipulate the preboot environment, overwrite UEFI Secure Boot-related memory values, and execute unauthorized software on the affected device.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **cisco-sa-ucs-uefi-sb-bypass-eb6xC5GW** · Cisco · affected: Cisco Unified Computing System E-Series Software (UCSE) (6 versions), Cisco Unified Computing System (Managed) (101 versions), Cisco Unified Computing System (Standalone) (180 versions), Cisco Enterprise NFV Infrastructure Software (63 versions) · updated 2026-09-15 · [advisory](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ucs-uefi-sb-bypass-eb6xC5GW)
