SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2016-8706

An integer overflow in process_bin_sasl_auth function in Memcached, which is responsible for authentication commands of Memcached binary protocol, can be abused to cause heap overflow and lead to remote code execution.

HIGH 8.1EPSS 45.7%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 45.7%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

An integer overflow in process_bin_sasl_auth function in Memcached, which is responsible for authentication commands of Memcached binary protocol, can be abused to cause heap overflow and lead to remote code execution.

CVSS 3.0
8.1 HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
45.70% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-190
Affected
memcached/memcached
Source
talos-cna@cisco.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.