CVE-2006-7246

Severity
6.8MEDIUM
EPSS
0.2%
top 57.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 27
Latest updateApr 21

Description

NetworkManager 0.9.x does not pin a certificate's subject to an ESSID when 802.11X authentication is used.

CVSS vector

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 1.6 | Impact: 5.2

Affected Packages5 packages

NVDgnome/networkmanager0.9.00.9.9.98
Debiannetwork-manager< 0.9.4.0-1+3
NVDopensuse/opensuse11.3, 11.4, 12.1+2

Patches

🔴Vulnerability Details

3
GHSA
GHSA-4fg6-64q2-8jgx: NetworkManager 02022-04-21
OSV
CVE-2006-7246: NetworkManager 02020-01-27
CVEList
CVE-2006-7246: NetworkManager 02020-01-27

📋Vendor Advisories

2
Red Hat
(WPA-Enterprise): Verify that the certificate is from trusted CA and matches the specified subject2006-05-10
Debian
CVE-2006-7246: network-manager - NetworkManager 0.9.x does not pin a certificate's subject to an ESSID when 802.1...2006

💬Community

1
Bugzilla
CVE-2006-7246 NetworkManager, wpa_supplicant (WPA-Enterprise): Verify that the certificate is from trusted CA and matches the specified subject2011-11-23