← voltar
CVE-2018-1111highCWE-77

CVE-2018-1111

78Vexday Risk Score

Corrija em breve. Ela tem exploit funcional público.

ssvc Attendcvss 7.5epss 98%
da publicação à arma0 dias
Publicada no NVD17 de mai.
1ª PoC17 de mai.
metasploit15 de mai.
probabilidade de exploração
98%top 1% das CVEs
exploração observada
nãonenhuma fonte reporta
7 exploit(s) público(s)
O que os fabricantes declaram (VEX)

Declarações oficiais dos fabricantes em formato CSAF/VEX: se o produto deles está afetado, já corrigido ou descartado — e por quê. É afirmação do fabricante, não juízo do Vexday.

Corrigido
47 produtos (399 componentes)
Red Hat Enterprise Linux Server (v. 7) · Red Hat Enterprise Linux Server EUS (v. 7.3) · Red Hat Enterprise Linux Server EUS (v. 7.4) · Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server (v. 7) · Red Hat Enterprise Linux Server (v. 6) · e outros 42
Não afetado
2 produtos (7 componentes)porque o código vulnerável não está presente no produto
Red Hat Enterprise Linux 8 · Red Hat Enterprise Linux 5
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration script included in the DHCP client. A malicious DHCP server, or an attacker on the local network able to spoof DHCP responses, could use this flaw to execute arbitrary commands with root privileges on systems using NetworkManager and configured to obtain network configuration using the DHCP protocol.
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.