PT-2018-7247 · Gigabyte · Gigabyte Brix Uefi Firmware
Alex Matrosov
·
Published
2018-07-09
·
Updated
2019-10-09
·
CVE-2017-3198
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
GIGABYTE BRIX UEFI firmware (affected versions not specified)
Description:
The issue concerns the lack of cryptographic validation of images prior to updating the system firmware. Furthermore, firmware updates are served over HTTP, which allows an attacker to make arbitrary modifications to firmware images without being detected.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Insufficient Verification of Data Authenticity
Missing Encryption of Sensitive Data
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gigabyte Brix Uefi Firmware