REDHAT-BUG-709662: Medium severity networkmanager vulnerability

Published Jun 1, 2011
·
Updated

It was found that NetworkManager, a network devices and connections manager, did not properly enforce the PolicyKit 'authadmin' action element settings (did not require authentication by an administrative user), when the 'authadmin' element was specified in org.freedesktop.network-manager-settings.system.wifi.share.open (connection sharing via an open WiFi network) action. A local attacker could use this flaw to setup an unsecure (passwordless) Ad-Hoc wireless network.

Affected Software

1 affected component
NetworkManager NetworkManager

Event History

Jun 1, 2011
Data Sourced
via Red Hat·10:28 AM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-709662?

The severity of REDHAT-BUG-709662 is considered to be high due to the improper enforcement of authentication settings.

2

How do I fix REDHAT-BUG-709662?

To fix REDHAT-BUG-709662, update the NetworkManager to the latest version where the authentication enforcement is properly implemented.

3

What systems are affected by REDHAT-BUG-709662?

REDHAT-BUG-709662 affects systems running NetworkManager that rely on PolicyKit for managing network devices and connections.

4

What is the impact of REDHAT-BUG-709662?

The impact of REDHAT-BUG-709662 allows non-administrative users to perform actions that should require elevated privileges, potentially compromising system security.

5

Is there a workaround for REDHAT-BUG-709662?

A possible workaround for REDHAT-BUG-709662 is to restrict access to the NetworkManager for non-administrative users until a patch is applied.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203