Security Advisory

CVE-2022-25213

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-03-07 21:55:25
Last updated 2024-08-03 04:36:06
Assigner tenable
CVSS score not scored
State PUBLISHED

Description

Improper physical access control and use of hard-coded credentials in /etc/passwd permits an attacker with physical access to obtain a root shell via an unprotected UART port on the device. The same port exposes an unauthenticated Das U-Boot BIOS shell.