CVE-2017-3198: GIGABYTE Gb-BSI7H-6500 Firmware

Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.

GIGABYTE BRIX UEFI firmware does not cryptographically validate images prior to updating the system firmware. Additionally, the firmware updates are served over HTTP. An attacker can make arbitrary modifications to firmware images without being detected.

Affected products

  • GIGABYTE Gb-BSI7H-6500 Firmware: version f6 only
  • GIGABYTE Gb-BXI7-5775 Firmware: version f2 only

Published 2018-07-09. Last modified 2026-06-17.