PT-2018-7246 · Gigabyte · Gigabyte Brix Uefi Firmware
Alex Matrosov
·
Published
2018-07-09
·
Updated
2019-10-09
·
CVE-2017-3197
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
GIGABYTE BRIX UEFI firmware for the GB-BSi7H-6500 version F6
GIGABYTE BRIX UEFI firmware for the GB-BXi7-5775 version F2
Description:
The issue concerns the insecure implementation of certain features in the UEFI firmware, specifically BIOSWE, BLE, SMM BWP, and PRx. This insecurity allows for arbitrary write access to the BIOS, potentially enabling modifications to the SPI flash.
Recommendations:
For GIGABYTE BRIX UEFI firmware for the GB-BSi7H-6500 version F6, consider restricting access to the BIOS to prevent unauthorized modifications until a secure update is available.
For GIGABYTE BRIX UEFI firmware for the GB-BXi7-5775 version F2, consider implementing additional security measures to protect the BIOS from arbitrary write access, such as secure boot mechanisms or flash protection, until a patch is released.
Exploit
Fix
Protection Mechanism Failure
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gigabyte Brix Uefi Firmware