lpar2rrd is a hardcoded system account in XoruX LPAR2RRD and STOR2RRD before 7.30.
The product stores sensitive information without properly limiting read or write access by unauthorized actors.
Link | Tags |
---|---|
https://stor2rrd.com/note730.php | release notes vendor advisory |
https://lpar2rrd.com/note730.php | release notes vendor advisory |
https://github.com/orangecertcc/security-research/security/advisories/GHSA-p2fq-9h5j-x6w5 | third party advisory |