REDHAT-BUG-709662: Medium severity networkmanager vulnerability
It was found that NetworkManager, a network devices and connections manager, did not properly enforce the PolicyKit 'authadmin' action element settings (did not require authentication by an administrative user), when the 'authadmin' element was specified in org.freedesktop.network-manager-settings.system.wifi.share.open (connection sharing via an open WiFi network) action. A local attacker could use this flaw to setup an unsecure (passwordless) Ad-Hoc wireless network.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-709662?
The severity of REDHAT-BUG-709662 is considered to be high due to the improper enforcement of authentication settings.
How do I fix REDHAT-BUG-709662?
To fix REDHAT-BUG-709662, update the NetworkManager to the latest version where the authentication enforcement is properly implemented.
What systems are affected by REDHAT-BUG-709662?
REDHAT-BUG-709662 affects systems running NetworkManager that rely on PolicyKit for managing network devices and connections.
What is the impact of REDHAT-BUG-709662?
The impact of REDHAT-BUG-709662 allows non-administrative users to perform actions that should require elevated privileges, potentially compromising system security.
Is there a workaround for REDHAT-BUG-709662?
A possible workaround for REDHAT-BUG-709662 is to restrict access to the NetworkManager for non-administrative users until a patch is applied.