PT-2018-7247 · Gigabyte · Gigabyte Brix Uefi Firmware
Alex Matrosov
·
Publicado
2018-07-09
·
Atualizado
2019-10-09
·
CVE-2017-3198
CVSS v3.1
10
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
GIGABYTE BRIX UEFI firmware (affected versions not specified)
Description:
The issue concerns the lack of cryptographic validation of images prior to updating the system firmware. Furthermore, firmware updates are served over HTTP, which allows an attacker to make arbitrary modifications to firmware images without being detected.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Insufficient Verification of Data Authenticity
Missing Encryption of Sensitive Data
Improper Verification of Cryptographic Signature
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Gigabyte Brix Uefi Firmware