← back
CVE-2011-4182

shell code injection via ESSID because of missing escaping of a variable

CVSS 7.3 HIGHEPSS 1.8%CWE-77
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.3EPSS 1.8%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
12 Jun 2018Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Missing escaping of ESSID values in sysconfig of SUSE Linux Enterprise allows attackers controlling an access point to cause execute arbitrary code. Affected releases are sysconfig prior to 0.83.7-2.1.
CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N