USN-8806-1: NetworkManager vulnerability
Ubuntu fixed a NetworkManager flaw that could let a private 802.1X profile trust an attacker-chosen certificate authority.
Ubuntu published USN-8806-1 for a NetworkManager vulnerability in certificate-authority settings for private, single-user 802.1X connections. NetworkManager did not properly restrict ca-path and phase2-ca-path, allowing an attacker to point their own connection profile at a directory they control. NetworkManager could then trust an attacker-chosen certificate authority, and a rogue authentication server might expose network credentials. The notice does not report that the issue is being exploited.
- NetworkManager failed to restrict ca-path and phase2-ca-path on private 802.1X profiles.
- An attacker-controlled directory could make NetworkManager trust a chosen certificate authority.
- A rogue authentication server could then expose network credentials.
- The notice does not report active exploitation.
It was discovered that NetworkManager did not properly restrict the ca-path and phase2-ca-path certificate authority settings for private (single-user) 802.1X network connections. An attacker could use this issue to point their own private 802.1X connection profile at a directory under their control, causing NetworkManager to trust an attacker-chosen certificate authority and potentially exposing network credentials via a rogue authentication server.
This source does not provide full text. Read it at ubuntu.com.