A flaw was found in the libreswan client plugin for NetworkManager (NetkworkManager-libreswan), where it fails to properly sanitize the VPN configuration from the local unprivileged user. In this configuration, composed by a key-value format, the plugin fails to escape special characters, leading the application to interpret values as keys. One of the most critical parameters that could be abused by a malicious user is the `leftupdown`key. This key takes an executable command as a value and is used to specify what executes as a callback in NetworkManager-libreswan to retrieve configuration settings back to NetworkManager. As NetworkManager uses Polkit to allow an unprivileged user to control the system's network configuration, a malicious actor could achieve local privilege escalation and potential code execution as root in the targeted machine by creating a malicious configuration.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade NetworkManager-libreswan-gnomeUpgrade NetworkManager-libreswan | Oct 25, 2024 | Oct 22, 2024 |
| Amazon Linux Ami 2 | — | Upgrade NetworkManager-libreswan-gnomeUpgrade NetworkManager-libreswanUpgrade NetworkManager-libreswan-debuginfo | Dec 20, 2024 | Oct 22, 2024 |
| Oracle_linux | — | Upgrade NetworkManager-libreswan-gnomeUpgrade NetworkManager-libreswan | Nov 11, 2024 | Oct 22, 2024 |
| Redhat_linux | — | Upgrade NetworkManager-libreswan-debugsourceUpgrade NetworkManager-libreswan-debuginfoUpgrade NetworkManager-libreswanUpgrade NetworkManager-libreswan-gnome-debuginfoUpgrade NetworkManager-libreswan-gnome | Oct 24, 2024 | Oct 22, 2024 |
| Rocky_linux | — | Upgrade NetworkManager-libreswanUpgrade NetworkManager-libreswan-debugsourceUpgrade NetworkManager-libreswan-gnomeUpgrade NetworkManager-libreswan-gnome-debuginfoUpgrade NetworkManager-libreswan-debuginfo | Mar 18, 2025 | Oct 22, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub