CVE Vulnerabilities

CVE-2006-7246

Improper Certificate Validation

Published: Jan 27, 2020 | Modified: Jan 31, 2020
CVSS 3.x
6.8
MEDIUM
Source:
NVD
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
3.2 LOW
AV:A/AC:H/Au:N/C:P/I:P/A:N
RedHat/V2
4 MODERATE
AV:N/AC:H/Au:N/C:P/I:P/A:N
RedHat/V3
Ubuntu
LOW

NetworkManager 0.9.x does not pin a certificates subject to an ESSID when 802.11X authentication is used.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Networkmanager Gnome 0.9.0 (including) 0.9.9.98 (including)
Network-manager Ubuntu hardy *
Network-manager Ubuntu lucid *
Network-manager Ubuntu natty *

Potential Mitigations

References