CVE-2017-3198: GIGABYTE BRIX UEFI firmware is not cryptographically signed
GIGABYTE BRIX UEFI firmware does not cryptographically validate images prior to updating the system firmware. Additionally, the firmware updates are served over HTTP. An attacker can make arbitrary modifications to firmware images without being detected.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3198?
CVE-2017-3198 has been classified as a high severity vulnerability due to the potential for unauthorized firmware modifications.
How do I fix CVE-2017-3198?
To mitigate CVE-2017-3198, ensure that you update the firmware using a secure method and validate the updates' integrity.
What is the impact of CVE-2017-3198?
The impact of CVE-2017-3198 includes the possibility of malicious firmware alterations that could compromise system integrity.
Which devices are affected by CVE-2017-3198?
CVE-2017-3198 affects specific Gigabyte BRIX UEFI firmware versions including f6 for GB-BSI7H-6500 and f2 for GB-BXI7-5775.
Is CVE-2017-3198 a remote attack vulnerability?
Yes, CVE-2017-3198 allows attackers to exploit the vulnerability remotely due to firmware updates being served over HTTP.