← back
CVE-2018-1111highCWE-77

CVE-2018-1111

78Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendcvss 7.5epss 98%
from disclosure to weapon0 days
Published on NVDMay 17
1st PoCMay 17
metasploitMay 15
exploitation probability
98%top 1% of all CVEs
observed exploitation
nono source reports it
7 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Fixed
47 products (399 components)
Red Hat Enterprise Linux Server (v. 7) · Red Hat Enterprise Linux Server EUS (v. 7.3) · Red Hat Enterprise Linux Server EUS (v. 7.4) · Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server (v. 7) · Red Hat Enterprise Linux Server (v. 6) · and others 42
Not affected
2 products (7 components)because the vulnerable code is not present in the product
Red Hat Enterprise Linux 8 · Red Hat Enterprise Linux 5
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration script included in the DHCP client. A malicious DHCP server, or an attacker on the local network able to spoof DHCP responses, could use this flaw to execute arbitrary commands with root privileges on systems using NetworkManager and configured to obtain network configuration using the DHCP protocol.
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.