CVE-2020-10754: Fedoraproject Fedora
Medium severity, CVSS 4.3. EPSS: 1% chance of exploitation in the next 30 days.
It was found that nmcli, a command line interface to NetworkManager did not honour 802-1x.ca-path and 802-1x.phase2-ca-path settings, when creating a new profile. When a user connects to a network using this profile, the authentication does not happen and the connection is made insecurely.
Affected products
- Fedoraproject Fedora: version 31 only
- Gnome Networkmanager: before 1.22.14 (fixed in 1.22.14); from 1.24.0, before 1.24.2 (fixed in 1.24.2)
Published 2020-06-08. Last modified 2026-06-17.