// For flags

CVE-2011-2176

NetworkManager: Did not honour PolicyKit auth_admin action element by creation of Ad-Hoc wireless networks

Severity Score

9.1
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

GNOME NetworkManager before 0.8.6 does not properly enforce the auth_admin element in PolicyKit, which allows local users to bypass intended wireless network sharing restrictions via unspecified vectors.

GNOME NetworkManager antes de v0.8.6 G no aplica correctamente el elemento auth_admin de PolicyKit, lo que permite a usuarios locales eludir restricciones intencionadas en el intercambio de redes inalámbricas a través de vectores no especificados.

NetworkManager is a network link manager that attempts to keep a wired or wireless network connection active at all times. It was found that NetworkManager did not properly enforce PolicyKit settings controlling the permissions to configure wireless network sharing. A local, unprivileged user could use this flaw to bypass intended PolicyKit restrictions, allowing them to enable wireless network sharing. Users of NetworkManager should upgrade to these updated packages, which contain a backported patch to correct this issue. Running instances of NetworkManager must be restarted for this update to take effect. Various other issues were also addressed.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2011-05-31 CVE Reserved
  • 2011-07-13 CVE Published
  • 2024-08-06 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-287: Improper Authentication
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Gnome
Search vendor "Gnome"
Networkmanager
Search vendor "Gnome" for product "Networkmanager"
<= 0.8.4
Search vendor "Gnome" for product "Networkmanager" and version " <= 0.8.4"
-
Affected
Gnome
Search vendor "Gnome"
Networkmanager
Search vendor "Gnome" for product "Networkmanager"
0.2.0
Search vendor "Gnome" for product "Networkmanager" and version "0.2.0"
-
Affected
Gnome
Search vendor "Gnome"
Networkmanager
Search vendor "Gnome" for product "Networkmanager"
0.3.0
Search vendor "Gnome" for product "Networkmanager" and version "0.3.0"
-
Affected
Gnome
Search vendor "Gnome"
Networkmanager
Search vendor "Gnome" for product "Networkmanager"
0.3.1
Search vendor "Gnome" for product "Networkmanager" and version "0.3.1"
-
Affected
Gnome
Search vendor "Gnome"
Networkmanager
Search vendor "Gnome" for product "Networkmanager"
0.4.1
Search vendor "Gnome" for product "Networkmanager" and version "0.4.1"
-
Affected
Gnome
Search vendor "Gnome"
Networkmanager
Search vendor "Gnome" for product "Networkmanager"
0.5.0
Search vendor "Gnome" for product "Networkmanager" and version "0.5.0"
-
Affected
Gnome
Search vendor "Gnome"
Networkmanager
Search vendor "Gnome" for product "Networkmanager"
0.5.1
Search vendor "Gnome" for product "Networkmanager" and version "0.5.1"
-
Affected
Gnome
Search vendor "Gnome"
Networkmanager
Search vendor "Gnome" for product "Networkmanager"
0.6.0
Search vendor "Gnome" for product "Networkmanager" and version "0.6.0"
-
Affected
Gnome
Search vendor "Gnome"
Networkmanager
Search vendor "Gnome" for product "Networkmanager"
0.6.1
Search vendor "Gnome" for product "Networkmanager" and version "0.6.1"
-
Affected
Gnome
Search vendor "Gnome"
Networkmanager
Search vendor "Gnome" for product "Networkmanager"
0.6.2
Search vendor "Gnome" for product "Networkmanager" and version "0.6.2"
-
Affected
Gnome
Search vendor "Gnome"
Networkmanager
Search vendor "Gnome" for product "Networkmanager"
0.6.6
Search vendor "Gnome" for product "Networkmanager" and version "0.6.6"
-
Affected
Gnome
Search vendor "Gnome"
Networkmanager
Search vendor "Gnome" for product "Networkmanager"
0.7.0
Search vendor "Gnome" for product "Networkmanager" and version "0.7.0"
-
Affected
Gnome
Search vendor "Gnome"
Networkmanager
Search vendor "Gnome" for product "Networkmanager"
0.7.1
Search vendor "Gnome" for product "Networkmanager" and version "0.7.1"
-
Affected
Gnome
Search vendor "Gnome"
Networkmanager
Search vendor "Gnome" for product "Networkmanager"
0.7.2
Search vendor "Gnome" for product "Networkmanager" and version "0.7.2"
-
Affected
Gnome
Search vendor "Gnome"
Networkmanager
Search vendor "Gnome" for product "Networkmanager"
0.8.1
Search vendor "Gnome" for product "Networkmanager" and version "0.8.1"
-
Affected
Gnome
Search vendor "Gnome"
Networkmanager
Search vendor "Gnome" for product "Networkmanager"
0.8.2
Search vendor "Gnome" for product "Networkmanager" and version "0.8.2"
-
Affected