Hardware & Firmware Policy
AMI APTIO
Shell Boot Entry Exposed
Embedded shell mapped in BootOrder
NVRAM Variable Lock
Protects Boot#### from untrusted edits
Deterministic Verification State
Vulnerability Status:
Vulnerable
Bypass Vector:
Embedded UEFI Shell Boot Entry
OS Exec Prevented:
true
Mitigation Readiness:
Action Required: Lock NVRAM variables and disable external shell paths.
Execution Graph: Pre-Boot vs OS Verification
STANDBY
Active Vendor
AMI
Security State
BYPASS RISK HIGH
AUTHENTICATED
NVRAM UNLOCKED
BYPASS TRIGGERED
PREVENTED / SKIPPED
[SEC] Platform Reset Vector @ 0xFFFFFFF0
[PEI] Memory Initialization Completed (16384 MB)
[DXE] Loading DXE Core... VariableStoreProtocol active
[BDS] WARNING: Shell boot option enabled in BootOrder (Boot0001)
[BYPASS] Interactive Shell launched: script overrides active policy!
[EXEC] Running unauthorized binary: fs0:\efi\boot\payload.efi
[SECURITY] Secure Boot signature validation never invoked. OS handoff abandoned.
Mitigation & Audit Control
Validate adherence against CERT/CC VU#987231 advisory recommendations for enterprise firmware deployments.
Disable Embedded Shell in BootOrder
Remove Shell entry from BDS menu & factory default list
Enforce VariableLockProtocol on NVRAM
Prevent runtime & OS-level modification of Boot#### variables
Apply DBX Revocation List
Blacklist known vulnerable firmware binaries & boot shims
TPM PCR[4] Boot Flow Measurement
Verify measured boot attestation fails if shell executes
Complies with NIST SP 800-147B and CERT/CC VU#987231