CVE-2020-10754

EUVD-2020-3172
It was found that nmcli, a command line interface to NetworkManager did not honour 802-1x.ca-path and 802-1x.phase2-ca-path settings, when creating a new profile. When a user connects to a network using this profile, the authentication does not happen and the connection is made insecurely.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
redhatCNA
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 48%
Affected Products (NVD)
VendorProductVersion
gnomenetworkmanager
𝑥
< 1.22.14
gnomenetworkmanager
1.24.0 ≤
𝑥
< 1.24.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
network-manager
bookworm
1.42.4-1
fixed
bullseye
1.30.6-1+deb11u1
fixed
sid
1.50.0-1
fixed
trixie
1.50.0-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
network-manager
bionic
not-affected
eoan
not-affected
focal
not-affected
trusty
dne
xenial
not-affected