CVE-2018-1111
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration...
- Published
- May 17, 2018
- Updated
- Aug 5, 2024
- Assigning CNA
- redhat
- Evidence observed
- May 18, 2018
Primary CVSS
nvd · CVSS 2.0
AV:A/AC:M/Au:N/C:C/I:C/A:CHigh · next 30 days
- Percentile
- 99.9%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration script included in the DHCP client. A malicious DHCP server, or an attacker on the local network able to spoof DHCP responses, could use this flaw to execute arbitrary commands with root privileges on systems using NetworkManager and configured to obtain network configuration using the DHCP protocol.
Sources
5- CVE-2018-1111Exploit
Ruby-based exploit for CVE-2018-1111 (DynoRoot) targeting DHCP client vulnerability in Red Hat-based systems to gain root access via malicious DHCP responses.
Docker-based lab environment to reproduce and exploit CVE-2018-1111 (DynoRoot) with automated attacker and victim scripts for hands-on security training.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.