Back to search
CVE-2022-3287
Published: Sep 28, 2022
Modified: May 20, 2025
PUBLISHED
Description
When creating an OPERATOR user account on the BMC, the redfish plugin saved the auto-generated password to /etc/fwupd/redfish.conf without proper restriction, allowing any user on the system to read the same configuration file.
| Vendor | Product | Versions |
|---|---|---|
n/a | fwupd | affected Fixed in version 1.8.5 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now