CVE Database
/

CVE-2017-3198

Back to search

CVE-2017-3198

Published: Jul 9, 2018

Modified: Aug 5, 2024

PUBLISHED

Description

GIGABYTE BRIX UEFI firmware does not cryptographically validate images prior to updating the system firmware. Additionally, the firmware updates are served over HTTP. An attacker can make arbitrary modifications to firmware images without being detected.

VendorProductVersions

GIGABYTE

GB-BSi7H-6500

affected
F6

GIGABYTE

GB-BXi7-5775

affected
F2

Weaknesses (CWE)

References

VU#507496
third-party-advisory
x_refsource_CERT-VN
97294
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now