← back
CVE-2017-3198observed exploitationCWE-345

GIGABYTE BRIX UEFI firmware is not cryptographically signed

25Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Attendepss 1.6%
from disclosure to weapon
Published on NVDJul 9
VulnCheckMar 31
exploitation probability
1.6%top 27% of all CVEs
observed exploitation
yesVulnCheck
In short

GIGABYTE BRIX firmware updates are not digitally signed and are downloaded over unencrypted HTTP, allowing an attacker to modify the firmware without detection and compromise the system at the deepest level.

Technical detail

The UEFI firmware lacks cryptographic signature validation (CWE-345) and relies on insecure HTTP for distribution, enabling man-in-the-middle or supply-chain attackers to inject malicious firmware modifications that execute with maximum privilege during boot.

Summary generated and translated by AI from the official description.
GIGABYTE BRIX UEFI firmware does not cryptographically validate images prior to updating the system firmware. Additionally, the firmware updates are served over HTTP. An attacker can make arbitrary modifications to firmware images without being detected.