CVE-2018-1111
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration script included in the DHCP client. A malicious DHCP server, or an attacker on the local network able to spoof DHCP responses, could use this flaw to execute arbitrary commands with root privileges on systems using NetworkManager and configured to obtain network configuration using the DHCP protocol.
- Affected products
- Centos, Fedora, Networkmanager, Red Hat
- Fedoraproject Fedora
- = 26, 27, 28
- Fix
- Available
- CVSS 2.0
- 7.9 HIGH
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 98.0% (100th percentile)
- Weakness
- CWE-78, CWE-77
- NVD status
- Modified
- Published
- 2018-05-17
CVE-2018-1111 at NVD
16 known exploits for CVE-2018-1111
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2018-1111
CVE-2018-1111
FEP3370-advanced-ethical-hacking
DHCP Client - Command Injection (DynoRoot) Exploit
DHCP Client - Command Injection 'DynoRoot' (Metasploit)
DHCP Client Command Injection (DynoRoot)
Red Hat DHCP client NetworkManager integration script command injection
Red Hat DHCP client NetworkManager integration script command injection
Red Hat DHCP client NetworkManager integration script command injection
DynoRoot DHCP - Client Command Injection Exploit
DynoRoot DHCP Client - Command Injection
DynoRoot DHCP Client - Command Injection
DynoRoot DHCP Command Injection
Exploit for OS Command Injection in Fedoraproject Fedora
DHCP Client Script Code Execution Vulnerability(CVE-2018-1111)
DHCP Client Command Injection (DynoRoot)