SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-1111

DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration script included in the DHCP client.

HIGH 7.5EPSS 98.0%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 98.0%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.

Description

DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration script included in the DHCP client. A malicious DHCP server, or an attacker on the local network able to spoof DHCP responses, could use this flaw to execute arbitrary commands with root privileges on systems using NetworkManager and configured to obtain network configuration using the DHCP protocol.

CVSS 3.0
7.5 HIGHCVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
97.97% probability · 100th percentile
CISA KEV
Not listed
Weakness
CWE-77, CWE-78
Affected
fedoraproject/fedora · redhat/enterprise virtualization · redhat/enterprise virtualization host · redhat/enterprise linux · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux workstation
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.