Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
When creating an OPERATOR user account on the BMC, the redfish plugin saved the auto-generated password to /etc/fwupd/redfish.conf without proper restriction, allowing any user on the system to read the same configuration file.
CVSS Information
N/A
Vulnerability Type
明文存储口令
Vulnerability Title
fwupd 安全漏洞
Vulnerability Description
fwupd是一款支持Linux平台上的会话软件固件更新的插件。 fwupd存在安全漏洞,该漏洞源于在BMC上创建OPERATOR用户帐户时,redfish插件将自动生成的密码无限制地保存到/etc/fwupd/redfish.conf中,允许系统上的任何用户读取相同的配置文件。
CVSS Information
N/A
Vulnerability Type
N/A