This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Gnome First view 2005-08-01
Product Networkmanager Last view 2021-05-26
Version * Type Application
Update *  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:gnome:networkmanager

Activity : Overall

Related : CVE

  Date Alert Description
5.5 2021-05-26 CVE-2021-20297

A flaw was found in NetworkManager in versions before 1.30.0. Setting match.path and activating a profile crashes NetworkManager. The highest threat from this vulnerability is to system availability.

4.3 2020-06-08 CVE-2020-10754

It was found that nmcli, a command line interface to NetworkManager did not honour 802-1x.ca-path and 802-1x.phase2-ca-path settings, when creating a new profile. When a user connects to a network using this profile, the authentication does not happen and the connection is made insecurely.

5.5 2020-03-10 CVE-2012-1096

NetworkManager 0.9 and earlier allows local users to use other users' certificates or private keys when making a connection via the file path when adding a new connection.

6.8 2020-01-27 CVE-2006-7246

NetworkManager 0.9.x does not pin a certificate's subject to an ESSID when 802.11X authentication is used.

7.5 2018-03-20 CVE-2018-1000135

GNOME NetworkManager version 1.10.2 and earlier contains a Information Exposure (CWE-200) vulnerability in DNS resolver that can result in Private DNS queries leaked to local network's DNS servers, while on VPN. This vulnerability appears to have been fixed in Some Ubuntu 16.04 packages were fixed, but later updates removed the fix. cf. https://bugs.launchpad.net/ubuntu/+bug/1754671 an upstream fix does not appear to be available at this time.

2.1 2011-09-02 CVE-2011-2176

GNOME NetworkManager before 0.8.6 does not properly enforce the auth_admin element in PolicyKit, which allows local users to bypass intended wireless network sharing restrictions via unspecified vectors.

7.5 2005-08-01 CVE-2005-2410

Format string vulnerability in the nm_info_handler function in Network Manager may allow remote attackers to execute arbitrary code via format string specifiers in a Wireless Access Point identifier, which is not properly handled in a syslog call.

CWE : Common Weakness Enumeration

%idName
28% (2) CWE-295 Certificate Issues
28% (2) CWE-287 Improper Authentication
14% (1) CWE-306 Missing Authentication for Critical Function
14% (1) CWE-200 Information Exposure
14% (1) CWE-20 Improper Input Validation

Open Source Vulnerability Database (OSVDB)

id Description
77301 NetworkManager ESSID PEAP / EAP-TTLS 802.11x Authentication MitM Weakness
73318 NetworkManager PolicyKit auth_admin Enforcement Weakness
19020 Network Manager nm_info_handler Wireless Access Point Identifier Format String

OpenVAS Exploits

id Description
2012-06-06 Name : RedHat Update for NetworkManager RHSA-2011:0930-01
File : nvt/gb_RHSA-2011_0930-01_NetworkManager.nasl
2011-12-05 Name : SuSE Update for NetworkManager, wpa_supplicant, NetworkManager-gnome SUSE-SA:...
File : nvt/gb_suse_2011_045.nasl
2011-09-30 Name : Fedora Update for NetworkManager FEDORA-2011-13388
File : nvt/gb_fedora_2011_13388_NetworkManager_fc15.nasl
2011-08-18 Name : Fedora Update for NetworkManager FEDORA-2011-8612
File : nvt/gb_fedora_2011_8612_NetworkManager_fc14.nasl
2011-07-12 Name : Fedora Update for NetworkManager FEDORA-2011-9005
File : nvt/gb_fedora_2011_9005_NetworkManager_fc15.nasl

Nessus® Vulnerability Scanner

id Description
2016-04-05 Name: The remote Fedora host is missing one or more security updates.
File: fedora_2016-cd218eef79.nasl - Type: ACT_GATHER_INFO
2014-06-13 Name: The remote openSUSE host is missing a security update.
File: suse_11_4_NetworkManager-gnome-120110.nasl - Type: ACT_GATHER_INFO
2014-06-13 Name: The remote openSUSE host is missing a security update.
File: suse_11_4_NetworkManager-111104.nasl - Type: ACT_GATHER_INFO
2014-06-13 Name: The remote openSUSE host is missing a security update.
File: suse_11_3_NetworkManager-gnome-120110.nasl - Type: ACT_GATHER_INFO
2014-06-13 Name: The remote openSUSE host is missing a security update.
File: suse_11_3_NetworkManager-111104.nasl - Type: ACT_GATHER_INFO
2014-06-13 Name: The remote openSUSE host is missing a security update.
File: openSUSE-2011-15.nasl - Type: ACT_GATHER_INFO
2013-07-12 Name: The remote Oracle Linux host is missing one or more security updates.
File: oraclelinux_ELSA-2011-0930.nasl - Type: ACT_GATHER_INFO
2012-09-06 Name: The remote Mandriva Linux host is missing one or more security updates.
File: mandriva_MDVSA-2011-171.nasl - Type: ACT_GATHER_INFO
2012-08-01 Name: The remote Scientific Linux host is missing one or more security updates.
File: sl_20110712_NetworkManager_on_SL6_x.nasl - Type: ACT_GATHER_INFO
2012-02-20 Name: The remote SuSE 10 host is missing a security-related patch.
File: suse_NetworkManager-7957.nasl - Type: ACT_GATHER_INFO
2012-02-16 Name: The remote SuSE 11 host is missing a security update.
File: suse_11_NetworkManager-gnome-120110.nasl - Type: ACT_GATHER_INFO
2011-12-13 Name: The remote SuSE 11 host is missing one or more security updates.
File: suse_11_NetworkManager-111105.nasl - Type: ACT_GATHER_INFO
2011-12-13 Name: The remote SuSE 11 host is missing one or more security updates.
File: suse_11_NetworkManager-111104.nasl - Type: ACT_GATHER_INFO
2011-08-15 Name: The remote Fedora host is missing a security update.
File: fedora_2011-8612.nasl - Type: ACT_GATHER_INFO
2011-07-13 Name: The remote Red Hat host is missing one or more security updates.
File: redhat-RHSA-2011-0930.nasl - Type: ACT_GATHER_INFO
2011-07-07 Name: The remote Fedora host is missing a security update.
File: fedora_2011-9005.nasl - Type: ACT_GATHER_INFO
2005-07-31 Name: The remote Fedora Core host is missing a security update.
File: fedora_2005-680.nasl - Type: ACT_GATHER_INFO