CVE-2017-3197
CRITICAL EXPLOITED IN THE WILD RANSOMWAREGIGABYTE BRIX UEFI - Info Disclosure
Title source: llmExploitation Summary
CVE-2017-3197 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io), including in ransomware campaigns.
Description
GIGABYTE BRIX UEFI firmware for the GB-BSi7H-6500 (version F6) and GB-BXi7-5775 (version F2) platforms does not securely implement BIOSWE, BLE, SMM_BWP, and PRx features. As a result, the BIOS is not protected from arbitrary write access and may permit modifications to the SPI flash.
References (5)
Core 5
Core References
Exploit, Third Party Advisory x_refsource_misc
https://github.com/CylanceVulnResearch/disclosures/blob/master/CLVA-2017-01-001.md
Exploit, Third Party Advisory x_refsource_misc
https://github.com/CylanceVulnResearch/disclosures/blob/master/CLVA-2017-01-002.md
Third Party Advisory, US Government Resource third-party-advisory
x_refsource_cert-vn
https://www.kb.cert.org/vuls/id/507496
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/97294
Exploit, Third Party Advisory x_refsource_misc
https://www.cylance.com/en_us/blog/gigabyte-brix-systems-vulnerabilities.html
Scores
CVSS v3
9.8
EPSS
0.0532
EPSS Percentile
91.5%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
VulnCheck KEV
2017-03-31
InTheWild.io
2022-02-01
Ransomware Use
Confirmed
CWE
CWE-20
CWE-693
Status
published
Products (2)
gigabyte/gb-bsi7h-6500_firmware
f6
gigabyte/gb-bxi7-5775_firmware
f2
Published
Jul 09, 2018
Tracked Since
Feb 18, 2026