6.8
CVSSv2

CVE-2009-4144

Published: 23/12/2009 Updated: 19/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

NetworkManager (NM) 0.7.2 does not ensure that the configured Certification Authority (CA) certificate file for a (1) WPA Enterprise or (2) 802.1x network remains present upon a connection attempt, which might allow remote malicious users to obtain sensitive information or cause a denial of service (connectivity disruption) by spoofing the identity of a wireless network.

Vulnerable Product Search on Vulmon Subscribe to Product

gnome networkmanager 0.7.2

Vendor Advisories

Synopsis Moderate: NetworkManager security update Type/Severity Security Advisory: Moderate Topic Updated NetworkManager packages that fix two security issues are nowavailable for Red Hat Enterprise Linux 5This update has been rated as having moderate security impact by the RedHat Security Response Team ...
It was discovered that NetworkManager did not ensure that the Certification Authority (CA) certificate file remained present when using WPA Enterprise or 8021x networks A remote attacker could use this flaw to spoof the identity of a wireless network and view sensitive information (CVE-2009-4144) ...
Debian Bug report logs - #563371 CVE-2009-4145: information disclosure Package: network-manager-applet; Maintainer for network-manager-applet is Utopia Maintenance Team <pkg-utopia-maintainers@listsaliothdebianorg>; Reported by: Giuseppe Iuculano <iuculano@debianorg> Date: Sat, 2 Jan 2010 11:42:02 UTC Severity: ...
Debian Bug report logs - #560067 CVE-2009-4144: WPA enterprise network not verified when certificate is removed Package: network-manager-gnome; Maintainer for network-manager-gnome is Utopia Maintenance Team <pkg-utopia-maintainers@listsaliothdebianorg>; Source for network-manager-gnome is src:network-manager-applet (PTS, buildd, ...