NetworkManager: information disclosure by nm-connection-editor
Published Dec 23, 2009
2.1
LOWCVSS 2.0
EPSS 0.38%
Description
nm-connection-editor in NetworkManager (NM) 0.7.x exports connection objects over D-Bus upon actions in the connection editor GUI, which allows local users to obtain sensitive information by reading D-Bus signals, as demonstrated by using dbus-monitor to discover the password for the WiFi network.
Affected products
No data.
- 0.7.2
No data.
Red Hat Enterprise Linux 5
NetworkManager-1:0.7.0-9.el5_4
Fixed · RHSA-2010:0108
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | NetworkManager-1:0.7.0-9.el5_4 | Fixed | RHSA-2010:0108 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:L/AC:L/Au:N/C:P/I:N/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (10 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.38% (0.00383) | 29.94th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.38% (0.00383) | 29.90th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.06% (0.00061) | 16.26th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00042) | 5.07th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00042) | 5.63th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.28% (0.01282) | 68.34th | v2 (v2022.01.01) |
| Feb 13, 2023 | 1.28% (0.01282) | 67.79th | v2 (v2022.01.01) |
| Feb 3, 2023 | 1.55% (0.01547) | 74.40th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.28% (0.01282) | 65.91th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.28% (0.01282) | 41.72th | v2 (v2022.01.01) |
References (14)
- http://git.gnome.org/browse/network-manager-applet/commit/?h=NETWORKMANAGER_APPLET_0_7&id=56d87fcb86acb5359558e0a2ee702cfc0c3391f2 x_refsource_CONFIRMPatch
- http://git.gnome.org/browse/network-manager-applet/commit/?h=NETWORKMANAGER_APPLET_0_7&id=8627880e07c8345f69ed639325280c7f62a8f894 x_refsource_CONFIRMPatch
- http://lists.opensuse.org/opensuse-security-announce/2010-02/msg00000.html vendor-advisoryx_refsource_SUSE
- http://secunia.com/advisories/37819 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/38420 third-party-advisoryx_refsource_SECUNIA
- http://www.openwall.com/lists/oss-security/2009/12/16/3 mailing-listx_refsource_MLIST
- http://www.redhat.com/support/errata/RHSA-2010-0108.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/bid/37580 vdb-entryx_refsource_BID
- https://access.redhat.com/security/cve/CVE-2009-4145 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=546117 x_refsource_CONFIRMPatchIssue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/54898 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2009-4145
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10539 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2009-4145
Change history (0)
No recorded changes yet.