CVE-2011-4182
shell code injection via ESSID because of missing escaping of a variable
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.3EPSS 1.8%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
12 Jun 2018Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Missing escaping of ESSID values in sysconfig of SUSE Linux Enterprise allows attackers controlling an access point to cause execute arbitrary code. Affected releases are sysconfig prior to 0.83.7-2.1.
CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Affected products
SUSE Linux Enterprise · sysconfig