Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

2024 Audit- SEC-01-005 WP3: Boot Loader Password Not Set #7285

Open
zenmonkeykstop opened this issue Oct 29, 2024 · 0 comments
Open

2024 Audit- SEC-01-005 WP3: Boot Loader Password Not Set #7285

zenmonkeykstop opened this issue Oct 29, 2024 · 0 comments

Comments

@zenmonkeykstop
Copy link
Contributor

The boot loader lacks a password on the app (10.20.2.2) and mon (10.20.3.2) servers.
This enables unauthorized individuals with physical access to the server to set command
line boot parameters, potentially breaching system security.

Adding a boot loader password would provide extra protection in the event of someone getting temporary server access, but for it to make a significant difference we'd need other measures in place (for example, FDE). We will consider further work on this.

# for free to join this conversation on GitHub. Already have an account? # to comment
Projects
None yet
Development

No branches or pull requests

1 participant