DNA View

CVE-2006-7246

Medium
Low Medium High Critical
6.8
CVSS Score
Published: Jan 27, 2020
Last Modified: Nov 21, 2024

Vulnerability Description

NetworkManager 0.9.x does not pin a certificate's subject to an ESSID when 802.11X authentication is used.

CVSS Metrics

Common Vulnerability Scoring System

Vector String:

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Vector
A
Attack Complexity
H
Privileges Required
N
User Interaction
N
Scope
U
Confidentiality
H
Integrity
H
Availability
N

Known Affected Software

5 configuration(s) from 2 vendor(s)

opensuse
Version:
12.1
CPE:
cpe:2.3:o:opensuse:opensuse:12.1:*:*:*:*:*:*:*
opensuse
Version:
11.4
CPE:
cpe:2.3:o:opensuse:opensuse:11.4:*:*:*:*:*:*:*
opensuse
Version:
11.3
CPE:
cpe:2.3:o:opensuse:opensuse:11.3:*:*:*:*:*:*:*
linux_enterprise_server
Version:
11
CPE:
cpe:2.3:o:suse:linux_enterprise_server:11:sp1:*:*:-:*:*:*
linux_enterprise_desktop
Version:
11
CPE:
cpe:2.3:o:suse:linux_enterprise_desktop:11:-:*:*:*:*:*:*
This vulnerability affects 5 software configuration(s). Ensure you patch all affected systems.

Severity Details

6.8
out of 10.0
Medium

Weakness Type (CWE)

CWE-295 Top 25 #23

Improper Certificate Validation

Description
The product does not validate, or incorrectly validates, a certificate.
Typical Severity
High
OWASP Top 10
A02:2021-Cryptographic Failures
Abstraction Level
Base

Key Information

Published Date
January 27, 2020