Loading
GIGABYTE BRIX UEFI firmware does not cryptographically validate images prior to updating the system firmware. Additionally, the firmware updates are served over HTTP. An attacker can make arbitrary modifications to firmware images without being detected.
Use CWE-345, Gigabyte vendor hub and Gb-Bsi7h-6500 Firmware product page to widen CVE-2017-3198 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2017-3197 for nearby disclosures in the same product family.