CVE-2017-3198

GIGABYTE BRIX UEFI firmware does not cryptographically validate images prior to updating the system firmware. Additionally, the firmware updates are served over HTTP. An attacker can make arbitrary modifications to firmware images without being detected.
References
Link Resource
https://www.kb.cert.org/vuls/id/507496 Third Party Advisory US Government Resource
https://www.cylance.com/en_us/blog/gigabyte-brix-systems-vulnerabilities.html Exploit Third Party Advisory
http://www.securityfocus.com/bid/97294 Third Party Advisory VDB Entry
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:gigabyte:gb-bsi7h-6500_firmware:f6:*:*:*:*:*:*:*
cpe:2.3:h:gigabyte:gb-bsi7h-6500:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:gigabyte:gb-bxi7-5775_firmware:f2:*:*:*:*:*:*:*
cpe:2.3:h:gigabyte:gb-bxi7-5775:-:*:*:*:*:*:*:*

Information

Published : 2018-07-09 12:29

Updated : 2019-10-09 16:27


NVD link : CVE-2017-3198

Mitre link : CVE-2017-3198


JSON object : View

CWE
CWE-347

Improper Verification of Cryptographic Signature

CWE-311

Missing Encryption of Sensitive Data

Advertisement

dedicated server usa

Products Affected

gigabyte

  • gb-bsi7h-6500
  • gb-bxi7-5775_firmware
  • gb-bxi7-5775
  • gb-bsi7h-6500_firmware