CVE-2009-0365

nm-applet.conf in GNOME NetworkManager before 0.7.0.99 contains an incorrect deny setting, which allows local users to discover (1) network connection passwords and (2) pre-shared keys via calls to the GetSecrets method in the dbus request handler.

Published: 2009-03-04 Last update: 2026-06-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2009-0365 is rated Low Risk (37/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 0.78%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2009-0365

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 0.11% 0.78% +0.67%
2 2025-03-17 0.04% 0.11% +0.07%
3 2023-03-07 0.04%

Full EPSS history (4 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2009-0365

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
4.6 2.0 MEDIUM
AV:L/AC:L/Au:S/C:C/I:N/A:N Click to expand
Access vector (AV:L)
Requires local access to the target system.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:S)
A single authentication is required.
Confidentiality impact (C:C)
Complete confidentiality impact.
Integrity impact (I:N)
No integrity impact.
Availability impact (A:N)
No availability impact.
3.1 6.9 [email protected]

Weakness enumeration for CVE-2009-0365

OS Trackers for CVE-2009-0365

vendor priority summary link
debian medium CVE-2009-0365 medium priority: Debian including 2 source packages (network-manager, network-manager-applet), 10 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 10. https://security-tracker.debian.org/tracker/CVE-2009-0365
redhat medium https://access.redhat.com/security/cve/CVE-2009-0365
ubuntu medium CVE-2009-0365 medium priority: Ubuntu including 2 source packages (network-manager, network-manager-applet), 10 status rows across 5 suites (dapper, gutsy, hardy, intrepid, upstream): released 5, needs-triage 2, not-affected 2, DNE 1. https://ubuntu.com/security/CVE-2009-0365

Affected software / configurations for CVE-2009-0365

Vendor Product Version Raw CPE
ubuntu ubuntu_linux 6.06 cpe:2.3:o:ubuntu:ubuntu_linux:6.06:-:lts:*:*:*:*:*
ubuntu ubuntu_linux 7.10 cpe:2.3:o:ubuntu:ubuntu_linux:7.10:*:*:*:*:*:*:*
ubuntu ubuntu_linux 8.04 cpe:2.3:o:ubuntu:ubuntu_linux:8.04:-:lts:*:*:*:*:*
ubuntu ubuntu_linux 8.10 cpe:2.3:o:ubuntu:ubuntu_linux:8.10:*:*:*:*:*:*:*

References for CVE-2009-0365

URL Tags
http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00003.html
http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00010.html
http://secunia.com/advisories/34067
http://secunia.com/advisories/34177
http://secunia.com/advisories/34473
http://securitytracker.com/id?1021910
http://securitytracker.com/id?1021911
http://svn.gnome.org/viewvc/network-manager-applet/trunk/nm-applet.conf?r1=1133&r2=1207&pathrev=1207
http://svn.gnome.org/viewvc/network-manager-applet?view=revision&revision=1207
http://www.debian.org/security/2009/dsa-1955
http://www.redhat.com/support/errata/RHSA-2009-0361.html
http://www.redhat.com/support/errata/RHSA-2009-0362.html
http://www.securityfocus.com/bid/33966 Patch
http://www.securitytracker.com/id?1021908
http://www.ubuntu.com/usn/USN-727-1 Vendor Advisory
http://www.ubuntu.com/usn/USN-727-2 Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=487722
https://bugzilla.redhat.com/show_bug.cgi?id=487752
https://exchange.xforce.ibmcloud.com/vulnerabilities/49062
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10828
cvelogic Threat Intelligence