GIGABYTE BRIX UEFI firmware fails to securely implement BIOS write protection
Vulnerability Description
GIGABYTE BRIX UEFI firmware for the GB-BSi7H-6500 (version F6) and GB-BXi7-5775 (version F2) platforms does not securely implement BIOSWE, BLE, SMM_BWP, and PRx features. As a result, the BIOS is not protected from arbitrary write access and may permit modifications to the SPI flash.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-3197
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/CylanceVulnResearch/disclosures/blob/master/CLVA-2017-01-001.md
- https://github.com/CylanceVulnResearch/disclosures/blob/master/CLVA-2017-01-002.md
- https://www.kb.cert.org/vuls/id/507496
- http://www.securityfocus.com/bid/97294
- https://www.cylance.com/en_us/blog/gigabyte-brix-systems-vulnerabilities.html
More from GIGABYTE
View All →Affected Vendor
GIGABYTE
View all reports →