GIGABYTE BRIX UEFI firmware does not cryptographically validate images prior to updating the system firmware. Additionally, the firmware updates are served over HTTP. An attacker can make arbitrary modifications to firmware images without being detected.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HGigabyte Gb Bsi7h 6500
HWGigabyteall versionsGigabyte Gb Bsi7h 6500 Firmware
OSGigabytef6Gigabyte Gb Bxi7 5775
HWGigabyteall versionsGigabyte Gb Bxi7 5775 Firmware
OSGigabytef2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2017-3197CRITICAL9.8PL ✓same product
Gigabyte BRIX UEFI — brak ochrony zapisu BIOS/SPI flash
CVE-2018-19323CRITICAL9.8⚠ KEVPL ✓same vendor
Gigabyte GDrv — niekontrolowany dostęp do rejestrów MSR przez sterownik niskopoziomowy
CVE-2026-4415CRITICAL9.2PL ✓same vendor
Gigabyte Control Center — zapis dowolnych plików prowadzący do RCE lub privilege escalation
CVE-2018-19322HIGH7.8⚠ KEVsame vendor
The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE befo...
CVE-2018-19320HIGH7.8⚠ KEVsame vendor
The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTRE...