dhcp: Command injection vulnerability in the DHCP client NetworkManager integration script
Published May 17, 2018
7.5
HIGHCVSS 3.0
EPSS 97.86%
Description
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration script included in the DHCP client. A malicious DHCP server, or an attacker on the local network able to spoof DHCP responses, could use this flaw to execute arbitrary commands with root privileges on systems using NetworkManager and configured to obtain network configuration using the DHCP protocol.
Affected products
-
- Version Fedora 28StatusaffectedConstraints-
- Version
-
- Version Red Hat Enterprise Linux 6StatusaffectedConstraints-
- Version Red Hat Enterprise Linux 7StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
Configuration 1
- 26
- 27
- 28
Configuration 2
- 4.0
- 4.2
- 4.0
- 6.0
- 6.4
- 6.5
- 6.6
- 6.7
- 7.0
- 7.2
- 7.3
- 7.4
- 7.5
- 6.0
- 7.0
- 6.0
- 7.0
- 6.0
- 7.0
No data.
Red Hat Enterprise Linux 6
dhcp-12:4.1.1-53.P1.el6_9.4
Fixed · RHSA-2018:1454
Red Hat Enterprise Linux 6.4 Advanced Update Support
dhcp-12:4.1.1-34.P1.el6_4.2
Fixed · RHSA-2018:1461
Red Hat Enterprise Linux 6.5 Advanced Update Support
dhcp-12:4.1.1-38.P1.el6_5.1
Fixed · RHSA-2018:1460
Red Hat Enterprise Linux 6.6 Advanced Update Support
dhcp-12:4.1.1-43.P1.el6_6.2
Fixed · RHSA-2018:1459
Red Hat Enterprise Linux 6.6 Telco Extended Update Support
dhcp-12:4.1.1-43.P1.el6_6.2
Fixed · RHSA-2018:1459
Red Hat Enterprise Linux 6.7 Extended Update Support
dhcp-12:4.1.1-49.P1.el6_7.1
Fixed · RHSA-2018:1458
Red Hat Enterprise Linux 7
dhcp-12:4.2.5-68.el7_5.1
Fixed · RHSA-2018:1453
Red Hat Enterprise Linux 7.2 Advanced Update Support
dhcp-12:4.2.5-42.el7_2.1
Fixed · RHSA-2018:1457
Red Hat Enterprise Linux 7.2 Telco Extended Update Support
dhcp-12:4.2.5-42.el7_2.1
Fixed · RHSA-2018:1457
Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions
dhcp-12:4.2.5-42.el7_2.1
Fixed · RHSA-2018:1457
Red Hat Enterprise Linux 7.3 Extended Update Support
dhcp-12:4.2.5-47.el7_3.1
Fixed · RHSA-2018:1456
Red Hat Enterprise Linux 7.4 Extended Update Support
dhcp-12:4.2.5-58.el7_4.4
Fixed · RHSA-2018:1455
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7
imgbased-0:1.0.16-0.1.el7ev
Fixed · RHSA-2018:1524
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7
ovirt-node-ng-0:4.2.0-0.20170814.0.el7
Fixed · RHSA-2018:1524
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7
redhat-release-virtualization-host-0:4.2-3.0.el7
Fixed · RHSA-2018:1524
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7
redhat-virtualization-host-0:4.2-20180508.0
Fixed · RHSA-2018:1524
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7
rhvm-appliance-0:4.2-20180504.0
Fixed · RHSA-2018:1525
Red Hat Enterprise Linux 5
dhcp
Not affected
Red Hat Enterprise Linux 8
dhcp
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | dhcp-12:4.1.1-53.P1.el6_9.4 | Fixed | RHSA-2018:1454 |
| Red Hat Enterprise Linux 6.4 Advanced Update Support | dhcp-12:4.1.1-34.P1.el6_4.2 | Fixed | RHSA-2018:1461 |
| Red Hat Enterprise Linux 6.5 Advanced Update Support | dhcp-12:4.1.1-38.P1.el6_5.1 | Fixed | RHSA-2018:1460 |
| Red Hat Enterprise Linux 6.6 Advanced Update Support | dhcp-12:4.1.1-43.P1.el6_6.2 | Fixed | RHSA-2018:1459 |
| Red Hat Enterprise Linux 6.6 Telco Extended Update Support | dhcp-12:4.1.1-43.P1.el6_6.2 | Fixed | RHSA-2018:1459 |
| Red Hat Enterprise Linux 6.7 Extended Update Support | dhcp-12:4.1.1-49.P1.el6_7.1 | Fixed | RHSA-2018:1458 |
| Red Hat Enterprise Linux 7 | dhcp-12:4.2.5-68.el7_5.1 | Fixed | RHSA-2018:1453 |
| Red Hat Enterprise Linux 7.2 Advanced Update Support | dhcp-12:4.2.5-42.el7_2.1 | Fixed | RHSA-2018:1457 |
| Red Hat Enterprise Linux 7.2 Telco Extended Update Support | dhcp-12:4.2.5-42.el7_2.1 | Fixed | RHSA-2018:1457 |
| Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions | dhcp-12:4.2.5-42.el7_2.1 | Fixed | RHSA-2018:1457 |
| Red Hat Enterprise Linux 7.3 Extended Update Support | dhcp-12:4.2.5-47.el7_3.1 | Fixed | RHSA-2018:1456 |
| Red Hat Enterprise Linux 7.4 Extended Update Support | dhcp-12:4.2.5-58.el7_4.4 | Fixed | RHSA-2018:1455 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | imgbased-0:1.0.16-0.1.el7ev | Fixed | RHSA-2018:1524 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | ovirt-node-ng-0:4.2.0-0.20170814.0.el7 | Fixed | RHSA-2018:1524 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | redhat-release-virtualization-host-0:4.2-3.0.el7 | Fixed | RHSA-2018:1524 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | redhat-virtualization-host-0:4.2-20180508.0 | Fixed | RHSA-2018:1524 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | rhvm-appliance-0:4.2-20180504.0 | Fixed | RHSA-2018:1525 |
| Red Hat Enterprise Linux 5 | dhcp | Not affected | n/a |
| Red Hat Enterprise Linux 8 | dhcp | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat has been made aware of a vulnerability affecting the DHCP client packages as shipped with Red Hat Enterprise Linux 6 and 7. This vulnerability CVE-2018-1111 was rated as having a security impact of Critical. A malicious DHCP server, or an attacker on the local network able to spoof DHCP responses, could use this flaw to execute arbitrary commands with root privileges on systems using NetworkManager and configured to obtain network configuration using the DHCP protocol. Red Hat Enterprise Virtualization 4.1 includes the vulnerable components, but the default configuration is not impacted because NetworkManager is turned off in the Management Appliance, and not used in conjunction with DHCP in the Hypervisor. Customers can still obtain the updated packages from Red Hat Enterprise Linux channels using `yum update`, or upgrade to Red Hat Enterprise Virtualization 4.2, which includes the fixed packages. Red Hat Enterprise Virtualization 3.6 is not vulnerable as it does not use DHCP.
Red Hat mitigation
Please access https://access.redhat.com/security/vulnerabilities/3442151 for information on how to mitigate this issue.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
AV:A/AC:M/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (30 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 97.86% (0.97862) | 99.91th | v5 (v2026.06.15) |
| Jul 15, 2026 | 97.97% (0.97970) | 99.90th | v5 (v2026.06.15) |
| Jun 15, 2026 | 94.46% (0.94457) | 99.84th | v5 (v2026.06.15) |
| May 15, 2025 | 88.46% (0.88461) | 99.45th | v4 (v2025.03.14) |
| Mar 17, 2025 | 91.46% (0.91456) | 99.66th | v4 (v2025.03.14) |
| Dec 12, 2024 | 97.02% (0.97021) | 99.81th | v3 (v2023.03.01) |
| Jul 12, 2024 | 97.22% (0.97221) | 99.85th | v3 (v2023.03.01) |
| Apr 26, 2024 | 97.29% (0.97294) | 99.86th | v3 (v2023.03.01) |
| Jan 4, 2024 | 97.23% (0.97230) | 99.80th | v3 (v2023.03.01) |
| Dec 11, 2023 | 97.29% (0.97292) | 99.84th | v3 (v2023.03.01) |
| Nov 17, 2023 | 97.31% (0.97307) | 99.84th | v3 (v2023.03.01) |
| Oct 29, 2023 | 97.25% (0.97250) | 99.78th | v3 (v2023.03.01) |
| Oct 8, 2023 | 97.22% (0.97223) | 99.76th | v3 (v2023.03.01) |
| Sep 16, 2023 | 97.25% (0.97253) | 99.77th | v3 (v2023.03.01) |
| Aug 26, 2023 | 97.21% (0.97207) | 99.73th | v3 (v2023.03.01) |
| Aug 9, 2023 | 97.28% (0.97278) | 99.77th | v3 (v2023.03.01) |
| Jul 22, 2023 | 97.30% (0.97295) | 99.78th | v3 (v2023.03.01) |
| Jul 8, 2023 | 97.33% (0.97334) | 99.80th | v3 (v2023.03.01) |
| Jul 4, 2023 | 97.31% (0.97307) | 99.79th | v3 (v2023.03.01) |
| May 29, 2023 | 97.39% (0.97392) | 99.86th | v3 (v2023.03.01) |
| May 11, 2023 | 97.33% (0.97330) | 99.79th | v3 (v2023.03.01) |
| May 8, 2023 | 97.32% (0.97318) | 99.78th | v3 (v2023.03.01) |
| Apr 26, 2023 | 97.33% (0.97333) | 99.78th | v3 (v2023.03.01) |
| Apr 8, 2023 | 97.38% (0.97375) | 99.82th | v3 (v2023.03.01) |
| Mar 7, 2023 | 97.45% (0.97445) | 99.89th | v3 (v2023.03.01) |
| Mar 6, 2023 | 91.04% (0.91041) | 99.87th | v2 (v2022.01.01) |
| Feb 4, 2022 | 91.04% (0.91041) | 99.85th | v2 (v2022.01.01) |
| Feb 3, 2022 | 73.20% (0.73198) | 99.73th | v1 |
| Sep 1, 2021 | 73.20% (0.73198) | 99.85th | v1 |
| Apr 14, 2021 | 73.20% (0.73198) | 0.00th | v1 |
References (25)
- http://www.securityfocus.com/bid/104195 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1040912 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2018:1453 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:1454 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:1455 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:1456 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:1457 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:1458 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:1459 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:1460 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:1461 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:1524 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/security/cve/CVE-2018-1111 Vendor Advisory
- https://access.redhat.com/security/vulnerabilities/3442151 x_refsource_CONFIRMVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1567974 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1111 x_refsource_CONFIRMIssue TrackingVendor Advisory
- https://help.ecostruxureit.com/display/public/UADCE725/Security+fixes+in+StruxureWare+Data+Center+Expert+v7.6.0 x_refsource_CONFIRM
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CDCLLCHYFFXW354HMB5QBXOQOY5BH2EJ/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IDJA4QRR74TMXW34Q3DYYFPVBYRTJBI7/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QMTTB54QNTPD2SK6UL32EVQHMZP6BUUD/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2018-1111
- https://www.cve.org/CVERecord?id=CVE-2018-1111
- https://www.exploit-db.com/exploits/44652/ exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/44890/ exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
- https://www.tenable.com/security/tns-2018-10 x_refsource_CONFIRM
Change history (0)
No recorded changes yet.