CVE-2020-14156: High severity openbmc vulnerability
Published Jun 15, 2020
·Updated
userchannel/passwdmgr.cpp in OpenBMC phosphor-host-ipmid before 2020-04-03 does not ensure that /etc/ipmi-pass has strong file permissions.
Affected Software
1 affected component
Openbmc-project Openbmc<2020-04-03
Remediation
Event History
Jun 15, 2020
CVE Published
via MITRE·05:35 PM
Data Sourced
via MITRE·05:35 PM
Description
Frequently Asked Questions
1
What is CVE-2020-14156?
CVE-2020-14156 is a vulnerability in OpenBMC phosphor-host-ipmid before 2020-04-03 that allows unauthorized access to sensitive files.
2
How does CVE-2020-14156 affect OpenBMC?
CVE-2020-14156 affects OpenBMC versions before 2020-04-03 by not ensuring strong file permissions on the /etc/ipmi-pass file.
3
What is the severity of CVE-2020-14156?
CVE-2020-14156 has a severity rating of 8.8 (high).
4
How can I fix CVE-2020-14156?
To fix CVE-2020-14156, update to OpenBMC version 2020-04-03 or later and ensure proper file permissions on the /etc/ipmi-pass file.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2020-14156?
The Common Weakness Enumeration (CWE) ID for CVE-2020-14156 is CWE-276, which is for incorrect default permissions.