CVE-2022-3287

CVE Information
CVE ID
CVE-2022-3287
Severity
MEDIUM CVSS 6.5
Publish Date
2022-09-28
Description

When creating an OPERATOR user account on the BMC, the redfish plugin saved the auto-generated password to /etc/fwupd/redfish.conf without proper restriction, allowing any user on the system to read the same configuration file.

Collection Date
2026-01-13
Impact Summary
Affected Hosts 1
Related Incidents 0
Related Alerts 0
Affected Hosts (1)
Hostname OS Type Severity Total CVEs
in-bridge-40 LINUX CRITICAL 392