PT-2020-6870 · Unknown+4 · Networkmanager+4

Published

2020-05-17

·

Updated

2024-06-15

·

CVE-2020-10754

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Network Manager (affected versions not specified)
Description The issue is related to the nmcli command line interface of Network Manager, where incorrect settings are applied when creating a new profile. This allows a remote attacker to access confidential data. Specifically, nmcli does not honor the 802-1x.ca-path and 802-1x.phase2-ca-path settings when creating a new profile, resulting in insecure connections.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2862
BDU:2023-02641
CESA-2020_3011
CESA-2020_4003
CVE-2020-10754
MGASA-2020-0260
OPENSUSE-SU-2024:10602-1
RHSA-2020:3011
RHSA-2020:4003
RHSA-2020_3011
RHSA-2020_4003

Affected Products

Alt Linux
Astra Linux
Centos
Networkmanager
Red Hat