CVE-2022-25213

Publication date

2022-03-07 21:55:25

Family

tenable

State

PUBLISHED

Description

Improper physical access control and use of hard-coded credentials in /etc/passwd permits an attacker with physical access to obtain a root shell via an unprotected UART port on the device. The same port exposes an unauthenticated Das U-Boot BIOS shell.