CVE-2018-1111 is a critical command injection vulnerability affecting DHCP clients in Red Hat Enterprise Linux 6 and 7, and Fedora 28. A malicious DHCP server or an attacker on the local network can exploit this flaw to execute arbitrary commands with root privileges on vulnerable systems using NetworkManager. The vulnerability has a CVSS score of 7.5 (HIGH) due to its network-adjacent attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, public exploit modules exist for Metasploit and ExploitDB, indicating readily available exploit code. The high EPSS score, FAUCET Risk Score, and media coverage suggest significant community attention and a high likelihood of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
26CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:26:*:*:*:*:*:*:* | ||
27CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:27:*:*:*:*:*:*:* | ||
28CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:28:*:*:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:a:redhat:enterprise_virtualization:4.0:*:*:*:*:*:*:* | ||
4.2CPE matchmatch criteria | cpe:2.3:a:redhat:enterprise_virtualization:4.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.