PT-2022-7456 · Linux+7 · Fwupd+7
Hughsie
·
Published
2022-09-22
·
Updated
2025-05-20
·
CVE-2022-3287
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
fwupd (affected versions not specified)
Description
The issue is related to the fwupd daemon for managing firmware updates in Linux-based systems. When creating an OPERATOR user account on the BMC, the redfish plugin saves the auto-generated password to
/etc/fwupd/redfish.conf without proper restrictions. This allows any user on the system to read the same configuration file, potentially granting access to confidential information.Recommendations
For all affected versions, consider restricting access to the
/etc/fwupd/redfish.conf file to minimize the risk of exploitation. As a temporary workaround, limit the permissions of the redfish.conf file to prevent unauthorized users from reading the auto-generated password.Fix
Files Accessible to External Parties
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Centos
Debian
Red Hat
Red Os
Rocky Linux
Fwupd