CVE-2011-2176: Low severity red hat networkmanager-libreswan-gnome vulnerability

Published Jun 1, 2011
·
Updated

GNOME NetworkManager before 0.8.6 does not properly enforce the authadmin element in PolicyKit, which allows local users to bypass intended wireless network sharing restrictions via unspecified vectors.

Other sources

It was found that NetworkManager, a network devices and connections manager, did not properly enforce the PolicyKit 'authadmin' action element settings (did not require authentication by an administrative user), when the 'authadmin' element was specified in org.freedesktop.network-manager-settings.system.wifi.share.open (connection sharing via an open WiFi network) action. A local attacker could use this flaw to setup an unsecure (passwordless) Ad-Hoc wireless network.

Red Hat

Affected Software

16 affected components
Gnome NetworkManager=0.4.1
Gnome NetworkManager=0.3.1
Gnome NetworkManager=0.7.1
Gnome NetworkManager=0.8.2
Gnome NetworkManager=0.6.2
Gnome NetworkManager=0.8.1
Gnome NetworkManager=0.6.1
Gnome NetworkManager=0.7.2
Gnome NetworkManager=0.5.1
Gnome NetworkManager=0.2.0
Gnome NetworkManager=0.7.0
Gnome NetworkManager=0.5.0
Gnome NetworkManager=0.6.6
Gnome NetworkManager=0.3.0
Gnome NetworkManager=0.6.0
Gnome NetworkManager<=0.8.4

Event History

Jun 1, 2011
Data Sourced
10:28 AM
DescriptionSeverityAffected Software
Sep 2, 2011
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2011-2176?

CVE-2011-2176 is classified as a medium severity vulnerability allowing local users to bypass wireless network sharing restrictions.

2

How do I fix CVE-2011-2176?

To fix CVE-2011-2176, you should update NetworkManager to version 0.8.6 or later.

3

Which versions of NetworkManager are affected by CVE-2011-2176?

CVE-2011-2176 affects NetworkManager versions prior to 0.8.6, including multiple earlier versions.

4

What types of attacks does CVE-2011-2176 allow?

CVE-2011-2176 allows local users to potentially bypass intended wireless network sharing restrictions.

5

Is CVE-2011-2176 a remote or local vulnerability?

CVE-2011-2176 is a local vulnerability, meaning it can be exploited by users with access to the local system.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203