Lucene search

K
cve[email protected]CVE-2011-2716
HistoryJul 03, 2012 - 4:40 p.m.

CVE-2011-2716

2012-07-0316:40:30
CWE-20
web.nvd.nist.gov
154
busybox
dhcp
remote code execution
vulnerability
cve-2011-2716

6.8 Medium

CVSS2

Attack Vector

ADJACENT_NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:A/AC:H/Au:N/C:C/I:C/A:C

7.7 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

57.6%

The DHCP client (udhcpc) in BusyBox before 1.20.0 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in the (1) HOST_NAME, (2) DOMAIN_NAME, (3) NIS_DOMAIN, and (4) TFTP_SERVER_NAME host name options.

Affected configurations

NVD
Node
t-mobiletm-ac1900Match3.0.0.4.376_3169
Node
busyboxbusyboxRange1.19.4
OR
busyboxbusyboxMatch0.60.5
OR
busyboxbusyboxMatch1.00
OR
busyboxbusyboxMatch1.0.0pre1
OR
busyboxbusyboxMatch1.0.0pre10
OR
busyboxbusyboxMatch1.0.0pre2
OR
busyboxbusyboxMatch1.0.0pre3
OR
busyboxbusyboxMatch1.0.0pre4
OR
busyboxbusyboxMatch1.0.0pre5
OR
busyboxbusyboxMatch1.0.0pre6
OR
busyboxbusyboxMatch1.0.0pre7
OR
busyboxbusyboxMatch1.0.0pre8
OR
busyboxbusyboxMatch1.0.0pre9
OR
busyboxbusyboxMatch1.0.0rc1
OR
busyboxbusyboxMatch1.0.0rc2
OR
busyboxbusyboxMatch1.0.0rc3
OR
busyboxbusyboxMatch1.01
OR
busyboxbusyboxMatch1.1.0
OR
busyboxbusyboxMatch1.1.0pre1
OR
busyboxbusyboxMatch1.1.1
OR
busyboxbusyboxMatch1.1.2
OR
busyboxbusyboxMatch1.1.3
OR
busyboxbusyboxMatch1.2.0
OR
busyboxbusyboxMatch1.2.1
OR
busyboxbusyboxMatch1.2.2
OR
busyboxbusyboxMatch1.2.2.1
OR
busyboxbusyboxMatch1.3.0
OR
busyboxbusyboxMatch1.3.1
OR
busyboxbusyboxMatch1.3.2
OR
busyboxbusyboxMatch1.4.0
OR
busyboxbusyboxMatch1.4.1
OR
busyboxbusyboxMatch1.4.2
OR
busyboxbusyboxMatch1.5.0
OR
busyboxbusyboxMatch1.5.1
OR
busyboxbusyboxMatch1.6.0
OR
busyboxbusyboxMatch1.6.1
OR
busyboxbusyboxMatch1.7.0
OR
busyboxbusyboxMatch1.7.1
OR
busyboxbusyboxMatch1.7.2
OR
busyboxbusyboxMatch1.7.3
OR
busyboxbusyboxMatch1.8.0
OR
busyboxbusyboxMatch1.8.1
OR
busyboxbusyboxMatch1.8.2
OR
busyboxbusyboxMatch1.9.0
OR
busyboxbusyboxMatch1.9.1
OR
busyboxbusyboxMatch1.9.2
OR
busyboxbusyboxMatch1.10.0
OR
busyboxbusyboxMatch1.10.1
OR
busyboxbusyboxMatch1.10.2
OR
busyboxbusyboxMatch1.10.3
OR
busyboxbusyboxMatch1.10.4
OR
busyboxbusyboxMatch1.11.0
OR
busyboxbusyboxMatch1.11.1
OR
busyboxbusyboxMatch1.11.2
OR
busyboxbusyboxMatch1.11.3
OR
busyboxbusyboxMatch1.12.0
OR
busyboxbusyboxMatch1.12.1
OR
busyboxbusyboxMatch1.12.2
OR
busyboxbusyboxMatch1.12.3
OR
busyboxbusyboxMatch1.12.4
OR
busyboxbusyboxMatch1.13.0
OR
busyboxbusyboxMatch1.13.1
OR
busyboxbusyboxMatch1.13.2
OR
busyboxbusyboxMatch1.13.3
OR
busyboxbusyboxMatch1.13.4
OR
busyboxbusyboxMatch1.14.0
OR
busyboxbusyboxMatch1.14.1
OR
busyboxbusyboxMatch1.14.2
OR
busyboxbusyboxMatch1.14.3
OR
busyboxbusyboxMatch1.14.4
OR
busyboxbusyboxMatch1.15.0
OR
busyboxbusyboxMatch1.15.1
OR
busyboxbusyboxMatch1.15.2
OR
busyboxbusyboxMatch1.15.3
OR
busyboxbusyboxMatch1.16.0
OR
busyboxbusyboxMatch1.16.1
OR
busyboxbusyboxMatch1.16.2
OR
busyboxbusyboxMatch1.17.0
OR
busyboxbusyboxMatch1.17.1
OR
busyboxbusyboxMatch1.17.2
OR
busyboxbusyboxMatch1.17.3
OR
busyboxbusyboxMatch1.17.4
OR
busyboxbusyboxMatch1.18.0
OR
busyboxbusyboxMatch1.18.1
OR
busyboxbusyboxMatch1.18.2
OR
busyboxbusyboxMatch1.18.3
OR
busyboxbusyboxMatch1.18.4
OR
busyboxbusyboxMatch1.18.5
OR
busyboxbusyboxMatch1.19.0
OR
busyboxbusyboxMatch1.19.2
OR
busyboxbusyboxMatch1.19.3

6.8 Medium

CVSS2

Attack Vector

ADJACENT_NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:A/AC:H/Au:N/C:C/I:C/A:C

7.7 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

57.6%