CVE Database
/

CVE-2018-1111

Back to search

CVE-2018-1111

Published: May 17, 2018

Modified: Aug 5, 2024

PUBLISHED

CVSS v3.0

7.5

HIGH

Description

DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration script included in the DHCP client. A malicious DHCP server, or an attacker on the local network able to spoof DHCP responses, could use this flaw to execute arbitrary commands with root privileges on systems using NetworkManager and configured to obtain network configuration using the DHCP protocol.

VendorProductVersions

Red Hat

dhcp

affected
Red Hat Enterprise Linux 6
affected
Red Hat Enterprise Linux 7

Fedora

dhcp

affected
Fedora 28

Weaknesses (CWE)

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector

Adjacent

Attack Complexity

High

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

References

FEDORA-2018-5392896132
vendor-advisory
x_refsource_FEDORA
104195
vdb-entry
x_refsource_BID
FEDORA-2018-23ca7a6798
vendor-advisory
x_refsource_FEDORA
1040912
vdb-entry
x_refsource_SECTRACK
RHSA-2018:1454
vendor-advisory
x_refsource_REDHAT
RHSA-2018:1455
vendor-advisory
x_refsource_REDHAT
RHSA-2018:1457
vendor-advisory
x_refsource_REDHAT
RHSA-2018:1459
vendor-advisory
x_refsource_REDHAT
RHSA-2018:1453
vendor-advisory
x_refsource_REDHAT
FEDORA-2018-36058ed9f2
vendor-advisory
x_refsource_FEDORA
RHSA-2018:1524
vendor-advisory
x_refsource_REDHAT
RHSA-2018:1456
vendor-advisory
x_refsource_REDHAT
RHSA-2018:1461
vendor-advisory
x_refsource_REDHAT
44652
exploit
x_refsource_EXPLOIT-DB
44890
exploit
x_refsource_EXPLOIT-DB
RHSA-2018:1458
vendor-advisory
x_refsource_REDHAT
RHSA-2018:1460
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now