PT-2018-7246 · Gigabyte · Gigabyte Brix Uefi Firmware

Alex Matrosov

·

Published

2018-07-09

·

Updated

2019-10-09

·

CVE-2017-3197

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: GIGABYTE BRIX UEFI firmware for the GB-BSi7H-6500 version F6 GIGABYTE BRIX UEFI firmware for the GB-BXi7-5775 version F2
Description: The issue concerns the insecure implementation of certain features in the UEFI firmware, specifically BIOSWE, BLE, SMM BWP, and PRx. This insecurity allows for arbitrary write access to the BIOS, potentially enabling modifications to the SPI flash.
Recommendations: For GIGABYTE BRIX UEFI firmware for the GB-BSi7H-6500 version F6, consider restricting access to the BIOS to prevent unauthorized modifications until a secure update is available. For GIGABYTE BRIX UEFI firmware for the GB-BXi7-5775 version F2, consider implementing additional security measures to protect the BIOS from arbitrary write access, such as secure boot mechanisms or flash protection, until a patch is released.

Exploit

Fix

Protection Mechanism Failure

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-3197

Affected Products

Gigabyte Brix Uefi Firmware