CVE-2022-3287
Published Sep 28, 2022When creating an OPERATOR user account on the BMC, the redfish plugin saved the auto-generated password to /etc/fwupd/redfish.conf without proper restriction, allowing any user on…
Vendor archive
1 CVEs tagged to vendor fwupd — 0 Critical, 0 High, 1 Medium, 0 Low, 0 Unrated.
When creating an OPERATOR user account on the BMC, the redfish plugin saved the auto-generated password to /etc/fwupd/redfish.conf without proper restriction, allowing any user on…