CVE-2018-4011 describes an integer underflow vulnerability in the mdnscap binary of the CUJO Smart Firewall, version 7003. This flaw, specifically CWE-191, occurs when parsing SRV records in mDNS packets, leading to an out-of-bounds access and a crash of the mdnscap process. With a CVSS score of 7.5 (High), this vulnerability can be triggered remotely by an unauthenticated attacker sending a specially crafted mDNS message, resulting in a denial of service. There is no evidence of active exploitation, no public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion, though it has received some media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7003CPE matchmatch criteria | cpe:2.3:a:getcujo:smart_firewall:7003:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.