« Volver al listado

CVE-2017-3197

Estado: ModificadaCrítica (9.8)—

GIGABYTE BRIX UEFI firmware for the GB-BSi7H-6500 (version F6) and GB-BXi7-5775 (version F2) platforms does not securely implement BIOSWE, BLE, SMM_BWP, and PRx features. As a result, the BIOS is not protected from arbitrary write access and may permit modifications to the SPI flash.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-3197",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 10,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cret@cert.org",
      "affectedData": [
        {
          "vendor": "GIGABYTE",
          "product": "GB-BSi7H-6500",
          "versions": [
            {
              "status": "affected",
              "version": "F6"
            }
          ]
        },
        {
          "vendor": "GIGABYTE",
          "product": "GB-BXi7-5775",
          "versions": [
            {
              "status": "affected",
              "version": "F2"
            }
          ]
        }
      ]
    }
  ],
  "published": "2018-07-09T19:29:00.247",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/97294",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "https://github.com/CylanceVulnResearch/disclosures/blob/master/CLVA-2017-01-001.md",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "https://github.com/CylanceVulnResearch/disclosures/blob/master/CLVA-2017-01-002.md",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "https://www.cylance.com/en_us/blog/gigabyte-brix-systems-vulnerabilities.html",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "https://www.kb.cert.org/vuls/id/507496",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/97294",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/CylanceVulnResearch/disclosures/blob/master/CLVA-2017-01-001.md",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/CylanceVulnResearch/disclosures/blob/master/CLVA-2017-01-002.md",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.cylance.com/en_us/blog/gigabyte-brix-systems-vulnerabilities.html",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.kb.cert.org/vuls/id/507496",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cret@cert.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-693"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "GIGABYTE BRIX UEFI firmware for the GB-BSi7H-6500 (version F6) and GB-BXi7-5775 (version F2) platforms does not securely implement BIOSWE, BLE, SMM_BWP, and PRx features. As a result, the BIOS is not protected from arbitrary write access and may permit modifications to the SPI flash."
    },
    {
      "lang": "es",
      "value": "El firmware de GIGABYTE BRIX UEFI para las plataformas GB-BSi7H-6500 (versión F6) y GB-BXi7-5775 (versión F2) no implementa las características BIOSWE, BLE, SMM_BWP, y PRx de manera segura. En consecuencia, la BIOS no está protegida del acceso de escritura arbitraria y podría permitir modificaciones en el flash SPI."
    }
  ],
  "lastModified": "2026-06-17T01:17:42.910",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:gigabyte:gb-bsi7h-6500_firmware:f6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A7A53C8F-B252-4602-9356-F77A7650F5D5"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:gigabyte:gb-bsi7h-6500:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "5B912BED-19DC-44B7-B06F-4CDF9135FB5B"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:gigabyte:gb-bxi7-5775_firmware:f2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "86E43347-B80C-45F4-AA26-A4ADA1F02CF2"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:gigabyte:gb-bxi7-5775:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "2564C261-8E5D-4EE6-A785-47DA1E7E0730"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cret@cert.org"
}