CVE-2009-4145

Severity
2.1LOW
EPSS
0.1%
top 80.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 23
Latest updateMay 2

Description

nm-connection-editor in NetworkManager (NM) 0.7.x exports connection objects over D-Bus upon actions in the connection editor GUI, which allows local users to obtain sensitive information by reading D-Bus signals, as demonstrated by using dbus-monitor to discover the password for the WiFi network.

CVSS vector

AV:L/AC:L/C:P/I:N/A:NExploitability: 3.9 | Impact: 2.9

Affected Packages2 packages

Debiannetwork-manager-applet< 0.7.2-2+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-2wgm-5xw3-53m2: nm-connection-editor in NetworkManager (NM) 02022-05-02
OSV
CVE-2009-4145: nm-connection-editor in NetworkManager (NM) 02009-12-23
CVEList
CVE-2009-4145: nm-connection-editor in NetworkManager (NM) 02009-12-23

📋Vendor Advisories

3
Ubuntu
network-manager-applet vulnerabilities2010-01-13
Red Hat
NetworkManager: information disclosure by nm-connection-editor2009-12-10
Debian
CVE-2009-4145: network-manager - nm-connection-editor in NetworkManager (NM) 0.7.x exports connection objects ove...2009

💬Community

1
Bugzilla
CVE-2009-4145 NetworkManager: information disclosure by nm-connection-editor2009-12-10
CVE-2009-4145 (LOW CVSS 2.1) | nm-connection-editor in NetworkMana | cvebase.io