VulnerabilityModified
CVE-2017-3198
An attacker can make arbitrary modifications to firmware images without being detected.
CRITICAL 9.8EPSS 1.60%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.60%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
GIGABYTE BRIX UEFI firmware does not cryptographically validate images prior to updating the system firmware. Additionally, the firmware updates are served over HTTP. An attacker can make arbitrary modifications to firmware images without being detected.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.60% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-345, CWE-311, CWE-347
- Affected
- gigabyte/gb-bsi7h-6500 firmware · gigabyte/gb-bxi7-5775 firmware
- Source
- cret@cert.org
References
- http://www.securityfocus.com/bid/97294Third Party Advisory, VDB Entry
- https://www.cylance.com/en_us/blog/gigabyte-brix-systems-vulnerabilities.htmlExploit, Third Party Advisory
- https://www.kb.cert.org/vuls/id/507496Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/97294Third Party Advisory, VDB Entry
- https://www.cylance.com/en_us/blog/gigabyte-brix-systems-vulnerabilities.htmlExploit, Third Party Advisory
- https://www.kb.cert.org/vuls/id/507496Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.