CVE-2022-3287

CVE-2022-3287

When creating an OPERATOR user account on the BMC, the redfish plugin saved the auto-generated password to /etc/fwupd/redfish.conf without proper restriction, allowing any user on the system to read the same configuration file.

Source: CVE-2022-3287

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다