CVE-2017-3197
HIGH 10.0EPSS 5.6%
GIGABYTE BRIX UEFI firmware for the GB-BSi7H-6500 (version F6) and GB-BXi7-5775 (version F2) platforms does not securely implement BIOSWE, BLE, SMM_BWP, and PRx features. As a result, the BIOS is not protected from arbitrary write access and may permit modifications to the SPI flash.
- CVSS v3.0
- 9.8 CRITICAL
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 10.0 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 5.64% chance of exploitation in the next 30 days, 92th percentile
- Published
- 2018-07-09
- Updated
- 2024-08-05
Proof-of-concept exploits (2)
- CylanceVulnResearch/disclosures/blob/master/CLVA-2017-01-002.md
- https://www.cylance.com/en_us/blog/gigabyte-brix-systems-vulnerabilities.html