CVE-2006-7246
Medium
Low
Medium
High
Critical
6.8
CVSS Score
Vulnerability Description
NetworkManager 0.9.x does not pin a certificate's subject to an ESSID when 802.11X authentication is used.
CVSS Metrics
Common Vulnerability Scoring System
Vector String:
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Vector
A
Attack Complexity
H
Privileges Required
N
User Interaction
N
Scope
U
Confidentiality
H
Integrity
H
Availability
N
Known Affected Software
5 configuration(s) from 2 vendor(s)
opensuse
Version:
12.1
CPE:
cpe:2.3:o:opensuse:opensuse:12.1:*:*:*:*:*:*:*
opensuse
Version:
11.4
CPE:
cpe:2.3:o:opensuse:opensuse:11.4:*:*:*:*:*:*:*
opensuse
Version:
11.3
CPE:
cpe:2.3:o:opensuse:opensuse:11.3:*:*:*:*:*:*:*
linux_enterprise_server
Version:
11
CPE:
cpe:2.3:o:suse:linux_enterprise_server:11:sp1:*:*:-:*:*:*
linux_enterprise_desktop
Version:
11
CPE:
cpe:2.3:o:suse:linux_enterprise_desktop:11:-:*:*:*:*:*:*
This vulnerability affects 5 software configuration(s). Ensure you patch all affected systems.
References & Resources
-
http://www.openwall.com/lists/oss-security/2010/04/22/2cve@mitre.org Mailing List Third Party Advisory
-
https://bugzilla.gnome.org/show_bug.cgi?id=341323cve@mitre.org Exploit Issue Tracking Patch Vendor Advisory
-
https://bugzilla.novell.com/show_bug.cgi?id=574266cve@mitre.org Exploit Issue Tracking Patch
-
https://lwn.net/Articles/468868/cve@mitre.org Exploit Patch Third Party Advisory
-
http://www.openwall.com/lists/oss-security/2010/04/22/2af854a3a-2127-422b-91ae-364da2661108 Mailing List Third Party Advisory
-
https://bugzilla.gnome.org/show_bug.cgi?id=341323af854a3a-2127-422b-91ae-364da2661108 Exploit Issue Tracking Patch Vendor Advisory
-
https://bugzilla.novell.com/show_bug.cgi?id=574266af854a3a-2127-422b-91ae-364da2661108 Exploit Issue Tracking Patch
-
https://lwn.net/Articles/468868/af854a3a-2127-422b-91ae-364da2661108 Exploit Patch Third Party Advisory
Severity Details
6.8
out of 10.0
Medium
Weakness Type (CWE)
CWE-295
Top 25 #23
Improper Certificate Validation
- Description
- The product does not validate, or incorrectly validates, a certificate.
- Typical Severity
- High
- OWASP Top 10
- A02:2021-Cryptographic Failures
- Abstraction Level
- Base
Key Information
- Published Date
- January 27, 2020
