Fwupd is a narrowly scoped firmware update utility for Linux systems that manages device firmware delivery and installation across heterogeneous hardware. Its observed vulnerability landscape centers on information-disclosure and credential-storage issues, including exposure of sensitive files or directories and plaintext password handling. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fwupd over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-3287MEDIUM When creating an OPERATOR user account on the BMC, the redfish plugin saved the auto-generated password to /etc/fwupd/redfish.conf without proper restriction, allowing any user on | Sep 28, 2022 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fwupd.
Media articles that mention a CVE ID that affects a product developed by Fwupd — matched by CVE ID, not by vendor name.