CVE-2018-1000115
Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDP support of the memcached server that can result in denial of service via network flood (traffic amplification of…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 88.1%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDP support of the memcached server that can result in denial of service via network flood (traffic amplification of 1:50,000 has been reported by reliable sources). This attack appear to be exploitable via network connectivity to port 11211 UDP. This vulnerability appears to have been fixed in 1.5.6 due to the disabling of the UDP protocol by default.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 88.11% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-400
- Affected
- memcached/memcached · canonical/ubuntu linux · debian/debian linux · redhat/openstack
- Source
- cve@mitre.org
References
- https://access.redhat.com/errata/RHBA-2018:2140Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1593Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1627Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2331Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2857Third Party Advisory
- https://blogs.akamai.com/2018/03/memcached-fueled-13-tbps-attacks.htmlThird Party Advisory
- https://github.com/memcached/memcached/commit/dbb7a8af90054bf4ef51f5814ef7ceb17d83d974Patch, Third Party Advisory
- https://github.com/memcached/memcached/issues/348Issue Tracking, Third Party Advisory
- https://github.com/memcached/memcached/wiki/ReleaseNotes156Third Party Advisory
- https://twitter.com/dormando/status/968579781729009664Third Party Advisory
- https://usn.ubuntu.com/3588-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4218Third Party Advisory
- https://www.exploit-db.com/exploits/44264/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/44265/Exploit, Third Party Advisory, VDB Entry
- https://www.synology.com/support/security/Synology_SA_18_07Third Party Advisory
- https://access.redhat.com/errata/RHBA-2018:2140Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1593Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1627Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2331Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2857Third Party Advisory
- https://blogs.akamai.com/2018/03/memcached-fueled-13-tbps-attacks.htmlThird Party Advisory
- https://github.com/memcached/memcached/commit/dbb7a8af90054bf4ef51f5814ef7ceb17d83d974Patch, Third Party Advisory
- https://github.com/memcached/memcached/issues/348Issue Tracking, Third Party Advisory
- https://github.com/memcached/memcached/wiki/ReleaseNotes156Third Party Advisory
- https://twitter.com/dormando/status/968579781729009664Third Party Advisory
- https://usn.ubuntu.com/3588-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4218Third Party Advisory
- https://www.exploit-db.com/exploits/44264/Exploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/44265/Exploit, Third Party Advisory, VDB Entry
- https://www.synology.com/support/security/Synology_SA_18_07Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.