PT-2022-7456 · Linux+7 · Fwupd+7

Hughsie

·

Published

2022-09-22

·

Updated

2025-05-20

·

CVE-2022-3287

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions fwupd (affected versions not specified)
Description The issue is related to the fwupd daemon for managing firmware updates in Linux-based systems. When creating an OPERATOR user account on the BMC, the redfish plugin saves the auto-generated password to /etc/fwupd/redfish.conf without proper restrictions. This allows any user on the system to read the same configuration file, potentially granting access to confidential information.
Recommendations For all affected versions, consider restricting access to the /etc/fwupd/redfish.conf file to minimize the risk of exploitation. As a temporary workaround, limit the permissions of the redfish.conf file to prevent unauthorized users from reading the auto-generated password.

Fix

Files Accessible to External Parties

Weakness Enumeration

Related Identifiers

ALSA-2023:2487
ALSA-2023:7189
ALT-PU-2022-2706
ALT-PU-2023-1166
BDU:2024-06519
CESA-2023_7189
CVE-2022-3287
OPENSUSE-SU-2024:12438-1
RHSA-2023:2487
RHSA-2023:7189
RHSA-2023_2487
RHSA-2023_7189
RHSA-2024:1106
RHSA-2024:1403
RLSA-2023:7189

Affected Products

Alt Linux
Almalinux
Centos
Debian
Red Hat
Red Os
Rocky Linux
Fwupd