CVE-2020-14156

Published
View on NVD ↗
CVSS v3
8.8
HIGH
CVSS v2
6.5
MEDIUM
Affected
2
PROJECTS

Description

user_channel/passwd_mgr.cpp in OpenBMC phosphor-host-ipmid before 2020-04-03 does not ensure that /etc/ipmi-pass has strong file permissions.

dbus-based ipmid for host-endpoint IPMI commands
GitHubGitHub
47
OpenBMC Distribution
GitHubGitHub
2.47K