Improper Authentication in NetworkManager



Published: 2011-09-03 | Updated: 2020-08-11
Risk Low
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2011-2176
CWE-ID CWE-287
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
NetworkManager
Server applications / Remote management servers, RDP, SSH

Vendor Gnome Development Team

Security Bulletin

This security bulletin contains one low risk vulnerability.

1) Improper Authentication

EUVDB-ID: #VU44756

Risk: Low

CVSSv3.1: 3.8 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2011-2176

CWE-ID: CWE-287 - Improper Authentication

Exploit availability: No

Description

The vulnerability allows a remote non-authenticated attacker to manipulate data.

GNOME NetworkManager before 0.8.6 does not properly enforce the auth_admin element in PolicyKit, which allows local users to bypass intended wireless network sharing restrictions via unspecified vectors.

Mitigation

Install update from vendor's website.

Vulnerable software versions

NetworkManager: 0.2.0 - 0.8.2

CPE2.3 External links

http://cgit.freedesktop.org/NetworkManager/NetworkManager/plain/NEWS?h=NM_0_8
http://lists.fedoraproject.org/pipermail/package-announce/2011-August/063665.html
http://secunia.com/advisories/44858
http://securitytracker.com/id?1025711
http://www.mandriva.com/security/advisories?name=MDVSA-2011:171
http://www.redhat.com/support/errata/RHSA-2011-0930.html
http://bugzilla.redhat.com/show_bug.cgi?id=709662


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

How the attacker can exploit this vulnerability?

The attacker would have to send a specially crafted request to the affected application in order to exploit this vulnerability.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###