CVE-2011-4182

HIGH

SUSE Linux Enterprise <0.83.7-2.1 - RCE

Title source: llm
STIX 2.1

Description

Missing escaping of ESSID values in sysconfig of SUSE Linux Enterprise allows attackers controlling an access point to cause execute arbitrary code. Affected releases are sysconfig prior to 0.83.7-2.1.

References (2)

Core 2
Core References
Issue Tracking x_refsource_confirm
https://bugzilla.suse.com/show_bug.cgi?id=735394
Various Sources x_refsource_confirm
https://www.suse.com/security/cve/CVE-2017-15710/

Scores

CVSS v3 7.3
EPSS 0.0176
EPSS Percentile 75.1%
Attack Vector ADJACENT_NETWORK
CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

Details

CWE
CWE-20 CWE-77
Status published
Products (1)
opensuse/sysconfig < 0.83.7
Published Jun 12, 2018
Tracked Since Feb 18, 2026