CVE-2022-3287
NixOS vulnerability analysis and mitigation

Overview

CVE-2022-3287 is a security vulnerability discovered in the fwupd package, which provides a service that allows session software to update device firmware. The vulnerability was identified when the redfish plugin saved an auto-generated password to /etc/fwupd/redfish.conf without proper restrictions, making it world-readable (Debian Security).

Technical details

The vulnerability occurs when creating an OPERATOR user account on the BMC (Baseboard Management Controller). The redfish plugin saves the auto-generated password to /etc/fwupd/redfish.conf with incorrect file permissions, allowing any user on the system to read the configuration file. The issue stems from the use of gfileset_contents() with a hardcoded mode of 0666, which overwrites the intended secure permissions (GitHub Commit).

Impact

The vulnerability allows unauthorized users on the system to read sensitive configuration files containing passwords, potentially compromising system security. The vulnerability has been assigned a CVSS v3 score of 5.5, indicating a moderate severity level (Red Hat CVE).

Mitigation and workarounds

The issue has been fixed in newer versions of the fwupd package. The fix involves using gfilesetcontentsfull() with the correct mode (0660) for newer GLib versions and providing a fallback with the same semantics for older versions. Red Hat has released security updates for affected versions, including fwupd version 1.7.8-2 for various architectures (Red Hat Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-48606HIGH7.8
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-48625HIGH7
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-48608MEDIUM5.5
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-48569MEDIUM5.5
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-65799MEDIUM4.3
  • NixOSNixOS
  • memos
NoYesDec 08, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management