CVE-2018-1160 is a critical out-of-bounds write vulnerability in Netatalk versions prior to 3.1.12, affecting products like Debian and Synology. This flaw allows a remote, unauthenticated attacker to achieve arbitrary code execution due to insufficient bounds checking on attacker-controlled data. With a CVSS score of 9.8 (Critical) and an EPSS score indicating high exploitability, it presents a significant risk. While not listed on CISA's KEV catalog, there are multiple public Proof-of-Concept exploits available on ExploitDB, though these are for authentication bypass rather than the described arbitrary code execution. The vulnerability has garnered notable community discussion and media coverage, including articles from BleepingComputer and SecurityWeek.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.1.12CPE matchmatch criteria | cpe:2.3:a:netatalk:netatalk:*:*:*:*:*:*:*:* | ||
>= 1.2, < 1.2-7742-5CPE matchmatch criteria | cpe:2.3:a:synology:router_manager:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:synology:skynas:-:*:*:*:*:*:*:* | ||
>= 5.2, < 5.2-5967-9CPE matchmatch criteria | cpe:2.3:o:synology:diskstation_manager:*:*:*:*:*:*:*:* | ||
>= 6.1, < 6.1.7-15284-3CPE matchmatch criteria | cpe:2.3:o:synology:diskstation_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.