peter bassill · operator
$ cve CVE-2018-1111 JSON

CVE-2018-1111 EXPLOIT

7.5
HIGH · CVSS 3.0 · EPSS 97.9% (pctl 100)

Patch early

A public exploit exists.

Description

DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration script included in the DHCP client. A malicious DHCP server, or an attacker on the local network able to spoof DHCP responses, could use this flaw to execute arbitrary commands with root privileges on systems using NetworkManager and configured to obtain network configuration using the DHCP protocol.

Scoring

CVSS7.5 (HIGH, v3.0)
VectorCVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS97.86% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-77
On CISA KEVno
Public exploityes
Published2018-05-17
Last modified2026-06-17

Affected (7)

VendorProduct
fedoraprojectfedora
redhatenterprise linux
redhatenterprise linux desktop
redhatenterprise linux server
redhatenterprise linux workstation
redhatenterprise virtualization
redhatenterprise virtualization host

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD