SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2009-0692

Stack-based buffer overflow in the script_write_params method in client/dhclient.c in ISC DHCP dhclient 4.1 before 4.1.0p1, 4.0 before 4.0.1p1, 3.1 before 3.1.2p1, 3.0, and 2.0 allows remote DHCP servers to execute arbitrary code via a crafted…

HIGH 10.0EPSS 25.8%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 25.8%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.

Description

Stack-based buffer overflow in the script_write_params method in client/dhclient.c in ISC DHCP dhclient 4.1 before 4.1.0p1, 4.0 before 4.0.1p1, 3.1 before 3.1.2p1, 3.0, and 2.0 allows remote DHCP servers to execute arbitrary code via a crafted subnet-mask option.

CVSS 2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
25.78% probability · 98th percentile
CISA KEV
Not listed
Weakness
CWE-119
Affected
isc/dhcp
Source
cret@cert.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.