VDB
CVE-2017-3197
CVE-2017-3197
PUBLISHED
CVSS 10 CRITICAL
GIGABYTE BRIX UEFI firmware for the GB-BSi7H-6500 (version F6) and GB-BXi7-5775 (version F2) platforms does not securely implement BIOSWE, BLE, SMM_BWP, and PRx features. As a result, the BIOS is not protected from arbitrary write access and may permit modifications to the SPI flash.
EPSS 2.84% · 86.5th percentile
Risk Scores
CVSS 2.0
10
EPSS Score
2.84%
86.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| gigabyte | gb-bxi7-5775_firmware | f2 |
| GIGABYTE | GB-BXi7-5775 | F2 |
| GIGABYTE | GB-BSi7H-6500 | F6 |
| gigabyte | gb-bsi7h-6500_firmware | f6 |
Timeline
- Mar 31, 2017 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Feb 28, 2022 EPSS Score
- May 2, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Nov 6, 2022 EPSS Score
- Jan 8, 2023 EPSS Score
- Mar 11, 2023 EPSS Score
References
- https://github.com/CylanceVulnResearch/disclosures/blob/master/CLVA-2017-01-001.md url
- https://github.com/CylanceVulnResearch/disclosures/blob/master/CLVA-2017-01-002.md url
- VU#507496 third-party-advisory
- 97294 vdb
- https://www.cylance.com/en_us/blog/gigabyte-brix-systems-vulnerabilities.html url
- https://nvd.nist.gov/vuln/detail/CVE-2017-3197 advisory