yocto ▾
›
kirkstone ▾
›
component
›
fwupd
Component Overview
Vulnerability Overview
Name
fwupd
Version
1.7.6
Type
library
Description
A simple daemon to allow session software to update firmware
Licenses
LGPL-2.1-or-later
PURL
-
CPE
cpe:2.3:*:fwupd:fwupd:1.7.6:*:*:*:*:*:*:*
Other Versions
#
Project
Branch
Version
yocto
master
2.0.19
yocto
scarthgap
1.9.18
Vulnerabilities
#
Name
Analysis
Description
CVE-2022-3287
Exploitable
When creating an OPERATOR user account on the BMC, the redfish plugin saved the auto-generated password to /etc/fwupd/redfish.conf without proper restriction, allowing any user on the system to read the same configuration file.