Insecure digital certificates In network-manager
Description
It was found that nmcli, a command line interface to NetworkManager did not honour 802-1x.ca-path and 802-1x.phase2-ca-path settings, when creating a new profile. When a user connects to a network using this profile, the authentication does not happen and the connection is made insecurely.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 11 | 1.24.2-1 | ||
debian 14 | 1.24.2-1 | ||
debian 12 | 1.24.2-1 | ||
debian 13 | 1.24.2-1 | ||
rpm rhel8 | 1:1.22.8-5.el8_2 | ||
rpm rhel7 | 1:1.18.8-1.el7 | ||
rpm rhel5 | - | - | |
rpm rhel6 | - | - |
Aliases
1. 2. 3. 4. 5.