Impact
NetworkManager failed to enforce the private_user restriction on the ca-path and phase2-ca-path directory properties of 802.1X WPA‑Enterprise connection profiles. A local unprivileged user can point a private connection’s CA path at a folder controlled by the attacker. This change bypasses server certificate validation, enabling an adversary to impersonate the wireless network and steal user credentials. The flaw stems from missing checks on private_user privilege (CWE‑863).
Affected Systems
The issue impacts Red Hat customers running Red Hat Enterprise Linux 6 through 10, Red Hat OpenShift Container Platform 4, Red Hat Hardened Images, and all associated networking packages provided by Red Hat. No specific version ranges are listed, meaning all current distributions that ship NetworkManager with the affected code paths are vulnerable.
Risk and Exploitability
The vulnerability is exploitable locally by any non‑privileged user who can modify a private WPA‑Enterprise profile. Successful exploitation allows an attacker to intercept or impersonate network traffic and capture authentication credentials. While no EPSS score or KEV listing is available, the absence of a public exploit combined with the ability to bypass certificate validation gives this flaw a high risk rating for organizations with wireless authentication. Until an official patch is released, administrators must rely on mitigations that prevent private profiles from using custom CA paths.
OpenCVE Enrichment