Description
When creating an OPERATOR user account on the BMC, the redfish plugin saved the auto-generated password to /etc/fwupd/redfish.conf without proper restriction, allowing any user on the system to read the same configuration file.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-42683 | When creating an OPERATOR user account on the BMC, the redfish plugin saved the auto-generated password to /etc/fwupd/redfish.conf without proper restriction, allowing any user on the system to read the same configuration file. |
References
History
Tue, 20 May 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-05-20T20:12:47.373Z
Reserved: 2022-09-23T00:00:00.000Z
Link: CVE-2022-3287
Updated: 2024-08-03T01:07:06.424Z
Status : Modified
Published: 2022-09-28T20:15:18.433
Modified: 2025-05-20T20:15:23.753
Link: CVE-2022-3287
OpenCVE Enrichment
No data.
EUVD