CVE-2020-14156: Openbmc-Project Openbmc
High severity, CVSS 8.8. EPSS: 1.8% chance of exploitation in the next 30 days.
user_channel/passwd_mgr.cpp in OpenBMC phosphor-host-ipmid before 2020-04-03 does not ensure that /etc/ipmi-pass has strong file permissions.
Affected products
- Openbmc-Project Openbmc: before 2020-04-03 (fixed in 2020-04-03)
Published 2020-06-15. Last modified 2026-06-17.