PT-2018-7247 · Gigabyte · Gigabyte Brix Uefi Firmware

Alex Matrosov

·

Publicado

2018-07-09

·

Atualizado

2019-10-09

·

CVE-2017-3198

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: GIGABYTE BRIX UEFI firmware (affected versions not specified)
Description: The issue concerns the lack of cryptographic validation of images prior to updating the system firmware. Furthermore, firmware updates are served over HTTP, which allows an attacker to make arbitrary modifications to firmware images without being detected.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Insufficient Verification of Data Authenticity

Missing Encryption of Sensitive Data

Improper Verification of Cryptographic Signature

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-3198

Produtos afetados

Gigabyte Brix Uefi Firmware