First published: Mon Jun 15 2020(Updated: )
user_channel/passwd_mgr.cpp in OpenBMC phosphor-host-ipmid before 2020-04-03 does not ensure that /etc/ipmi-pass has strong file permissions.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Openbmc-project Openbmc | <2020-04-03 |
https://github.com/openbmc/phosphor-host-ipmid/commit/b265455a2518ece7c004b43c144199ec980fc620
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-14156 is a vulnerability in OpenBMC phosphor-host-ipmid before 2020-04-03 that allows unauthorized access to sensitive files.
CVE-2020-14156 affects OpenBMC versions before 2020-04-03 by not ensuring strong file permissions on the /etc/ipmi-pass file.
CVE-2020-14156 has a severity rating of 8.8 (high).
To fix CVE-2020-14156, update to OpenBMC version 2020-04-03 or later and ensure proper file permissions on the /etc/ipmi-pass file.
The Common Weakness Enumeration (CWE) ID for CVE-2020-14156 is CWE-276, which is for incorrect default permissions.