« Back to list

CVE-2011-2176

Status: ModifiedLow (2.1)—

GNOME NetworkManager before 0.8.6 does not properly enforce the auth_admin element in PolicyKit, which allows local users to bypass intended wireless network sharing restrictions via unspecified vectors.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2011-2176",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 2.1,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2011-09-02T23:55:04.927",
  "references": [
    {
      "url": "http://cgit.freedesktop.org/NetworkManager/NetworkManager/plain/NEWS?h=NM_0_8",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2011-August/063665.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://secunia.com/advisories/44858",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://securitytracker.com/id?1025711",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2011:171",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.redhat.com/support/errata/RHSA-2011-0930.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=709662",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://cgit.freedesktop.org/NetworkManager/NetworkManager/plain/NEWS?h=NM_0_8",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2011-August/063665.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/44858",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securitytracker.com/id?1025711",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2011:171",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.redhat.com/support/errata/RHSA-2011-0930.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=709662",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "GNOME NetworkManager before 0.8.6 does not properly enforce the auth_admin element in PolicyKit, which allows local users to bypass intended wireless network sharing restrictions via unspecified vectors."
    },
    {
      "lang": "es",
      "value": "GNOME NetworkManager antes de v0.8.6 G no aplica correctamente el elemento auth_admin de PolicyKit, lo que permite a usuarios locales eludir restricciones intencionadas en el intercambio de redes inalámbricas a través de vectores no especificados."
    }
  ],
  "lastModified": "2026-06-16T23:30:51.850",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:gnome:networkmanager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1E52A487-28DE-4AC5-9E5E-136D089A9DD7",
              "versionEndIncluding": "0.8.4"
            },
            {
              "criteria": "cpe:2.3:a:gnome:networkmanager:0.2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E2923027-F6FF-4E15-8890-039EEEACBCCF"
            },
            {
              "criteria": "cpe:2.3:a:gnome:networkmanager:0.3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9007C9EF-299A-469A-AB8C-AC34F68ED66E"
            },
            {
              "criteria": "cpe:2.3:a:gnome:networkmanager:0.3.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CBBA10C9-1289-4ED5-8220-D64756363D89"
            },
            {
              "criteria": "cpe:2.3:a:gnome:networkmanager:0.4.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E9CA9051-FFFE-4A81-9DFB-5A88AFBCC9B6"
            },
            {
              "criteria": "cpe:2.3:a:gnome:networkmanager:0.5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "96BE22D8-3363-404F-BBA3-15ACEC476D42"
            },
            {
              "criteria": "cpe:2.3:a:gnome:networkmanager:0.5.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "684B1CD7-25AC-43B1-AF23-4F0DCF7ABF00"
            },
            {
              "criteria": "cpe:2.3:a:gnome:networkmanager:0.6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6F9C4E61-F66B-4190-8333-08282C97BF4D"
            },
            {
              "criteria": "cpe:2.3:a:gnome:networkmanager:0.6.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "059D401E-DAF3-4760-B6BF-243733C8169E"
            },
            {
              "criteria": "cpe:2.3:a:gnome:networkmanager:0.6.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4ACCB44D-9C94-44C0-9B66-B5F8B490FF91"
            },
            {
              "criteria": "cpe:2.3:a:gnome:networkmanager:0.6.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6C39C259-1527-4E37-9EBB-C1302429A822"
            },
            {
              "criteria": "cpe:2.3:a:gnome:networkmanager:0.7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2825F1D9-BE1F-42AA-A5C2-64099C371AB4"
            },
            {
              "criteria": "cpe:2.3:a:gnome:networkmanager:0.7.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "905E9021-3EF0-481E-966A-9343356D649E"
            },
            {
              "criteria": "cpe:2.3:a:gnome:networkmanager:0.7.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8D65E039-D608-4565-8E37-F0D65AC2BEE0"
            },
            {
              "criteria": "cpe:2.3:a:gnome:networkmanager:0.8.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BAC0EE7F-953B-4CF7-8F9F-C5FDE518CEEC"
            },
            {
              "criteria": "cpe:2.3:a:gnome:networkmanager:0.8.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "36B63323-1BC8-4644-9CFA-BC16F72B26C9"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}