CVE-2018-1111

HIGH IN THE WILD

DHCP Client Command Injection (DynoRoot)

Title source: metasploit

Description

DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration script included in the DHCP client. A malicious DHCP server, or an attacker on the local network able to spoof DHCP responses, could use this flaw to execute arbitrary commands with root privileges on systems using NetworkManager and configured to obtain network configuration using the DHCP protocol.

Exploits (6)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotelinux
https://www.exploit-db.com/exploits/44890
exploitdb WORKING POC VERIFIED
by Kevin Kirsche · pythonlocallinux
https://www.exploit-db.com/exploits/44652
nomisec WORKING POC 13 stars
by knqyf263 · poc
https://github.com/knqyf263/CVE-2018-1111
nomisec WORKING POC 12 stars
by kkirsche · poc
https://github.com/kkirsche/CVE-2018-1111
nomisec WORKING POC
by baldassarreFe · poc
https://github.com/baldassarreFe/FEP3370-advanced-ethical-hacking
metasploit WORKING POC EXCELLENT
by Felix Wilhelm · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/dhcp/rhel_dhcp_client_command_injection.rb

References (21)

... and 1 more

Scores

CVSS v3 7.5
EPSS 0.8823
EPSS Percentile 99.5%
Attack Vector ADJACENT_NETWORK
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

InTheWild.io 2018-07-16
CWE
CWE-78 CWE-77
Status published
Products (22)
fedoraproject/fedora 26
fedoraproject/fedora 27
fedoraproject/fedora 28
redhat/enterprise_linux 6.0
redhat/enterprise_linux 6.4
redhat/enterprise_linux 6.5
redhat/enterprise_linux 6.6
redhat/enterprise_linux 6.7
redhat/enterprise_linux 7.0
redhat/enterprise_linux 7.2
... and 12 more
Published May 17, 2018
Tracked Since Feb 18, 2026