Networkmanager

Vendor:

First CVE: Aug 1, 2005 · Active for 20 years

13
Total CVEs
More Total CVEs than 91% of tracked products
1.6
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
5.1
Avg CVSS
Higher Avg CVSS than 9% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Networkmanager over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 1, 2005
20 years ago
Most Recent CVE
May 26, 2021
1,885 days ago

CVE Severity & Scoring

Networkmanager13 CVEs
All CVEs352,231 CVEs
LowMediumHigh
Attack Vector
Local3 (23.1%)
Network2 (15.4%)
Unknown7 (53.8%)
Physical0 (0.0%)
Adjacent Network1 (7.7%)
Attack Complexity
Low5 (38.5%)
High1 (7.7%)
Unknown7 (53.8%)
User Interaction
None6 (46.2%)
Unknown7 (53.8%)
Required0 (0.0%)
Privileges Required
Low4 (30.8%)
High0 (0.0%)
None2 (15.4%)
Unknown7 (53.8%)

Top CVEs

Signals from CVEs in this product scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
NetworkManager 0.9 and earlier allows local users to use other users' certificates or private keys when making a connection via the file path when adding a new connection.
Mar 10, 20205.529NOYES
GNOME NetworkManager version 1.10.2 and earlier contains a Information Exposure (CWE-200) vulnerability in DNS resolver that can result in Private DNS queries leaked to local netwo
Mar 20, 20187.525NONO
Format string vulnerability in the nm_info_handler function in Network Manager may allow remote attackers to execute arbitrary code via format string specifiers in a Wireless Acces
Aug 1, 20057.524NONO
NetworkManager 0.9.x does not pin a certificate's subject to an ESSID when 802.11X authentication is used.
Jan 27, 20206.823NONO
Incomplete blacklist vulnerability in the svEscape function in settings/plugins/ifcfg-rh/shvar.c in the ifcfg-rh plug-in for GNOME NetworkManager 0.9.1, 0.9.0, 0.8.1, and possibly
Nov 4, 20116.922NONO
GNOME NetworkManager allows remote attackers to cause a denial of service (IPv6 traffic disruption) via a crafted MTU value in an IPv6 Router Advertisement (RA) message, a differen
Nov 17, 20155.021NONO
NetworkManager (NM) 0.7.2 does not ensure that the configured Certification Authority (CA) certificate file for a (1) WPA Enterprise or (2) 802.1x network remains present upon a co
Dec 23, 20096.821NONO
A flaw was found in NetworkManager in versions before 1.30.0. Setting match.path and activating a profile crashes NetworkManager. The highest threat from this vulnerability is to s
May 26, 20215.519NONO
It was found that nmcli, a command line interface to NetworkManager did not honour 802-1x.ca-path and 802-1x.phase2-ca-path settings, when creating a new profile. When a user conne
Jun 8, 20204.319NONO
In NetworkManager 0.9.2.0, when a new wireless network was created with WPA/WPA2 security in AdHoc mode, it created an open/insecure network.
Dec 26, 20194.418NONO

Exploit Exposure

Signals from CVEs in this product scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
7.7% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (13 CVEs).

Media Mentions

Signals from CVEs in this product scope (13 CVEs).

Top CNAs Publishing CVEs For Networkmanager

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
0.9.2.014.40.4%00
0.8.212.10.3%00
0.8.112.10.3%00
0.7.233.70.9%00
0.7.112.10.3%00
0.7.012.10.3%00
0.6.612.10.3%00
0.6.212.10.3%00
0.6.112.10.3%00
0.6.012.10.3%00
0.5.112.10.3%00
0.5.012.10.3%00
0.4.112.10.3%00
0.3.112.10.3%00
0.3.012.10.3%00
0.2.012.10.3%00