CVE-2017-3197: GIGABYTE BRIX UEFI firmware fails to securely implement BIOS write protection
GIGABYTE BRIX UEFI firmware for the GB-BSi7H-6500 (version F6) and GB-BXi7-5775 (version F2) platforms does not securely implement BIOSWE, BLE, SMMBWP, and PRx features. As a result, the BIOS is not protected from arbitrary write access and may permit modifications to the SPI flash.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3197?
CVE-2017-3197 is considered a high severity vulnerability due to its potential for arbitrary write access to the BIOS.
How do I fix CVE-2017-3197?
To mitigate CVE-2017-3197, update to the latest firmware versions F6 for GB-BSi7H-6500 or F2 for GB-BXi7-5775 provided by Gigabyte.
What platforms are affected by CVE-2017-3197?
CVE-2017-3197 affects the Gigabyte GB-BSi7H-6500 and GB-BXi7-5775 platforms with specific firmware versions.
What features are insecure in CVE-2017-3197?
CVE-2017-3197 has insecure implementations of BIOSWE, BLE, SMM_BWP, and PRx features.
What are the risks associated with CVE-2017-3197?
The risks of CVE-2017-3197 include unauthorized modifications to the SPI flash, potentially compromising system integrity.