PT-2018-7247 · Gigabyte · Gigabyte Brix Uefi Firmware

Alex Matrosov

·

Published

2018-07-09

·

Updated

2019-10-09

·

CVE-2017-3198

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: GIGABYTE BRIX UEFI firmware (affected versions not specified)
Description: The issue concerns the lack of cryptographic validation of images prior to updating the system firmware. Furthermore, firmware updates are served over HTTP, which allows an attacker to make arbitrary modifications to firmware images without being detected.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Insufficient Verification of Data Authenticity

Missing Encryption of Sensitive Data

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-3198

Affected Products

Gigabyte Brix Uefi Firmware