CVE-2018-1000115
high-risk
Published 2018-03-05
Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDP support of the memcached server that can result in denial of service via network flood (traffic amplification of 1:50,000 has been reported by reliable sources). This attack appear to be exploitable via network connectivity to port 11211 UDP. This vulnerability appears to have been fixed in 1.5.6 due to the disabling of the UDP protocol by default.
Do I need to act?
!
82.5% chance of exploitation in next 30 days
EPSS score — higher than 17% of all CVEs
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.5/10
High
NETWORK
/ LOW complexity
Affected Products (11)
References (30)
Third Party Advisory
https://access.redhat.com/errata/RHBA-2018:2140
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1593
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1627
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:2331
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:2857
Third Party Advisory
https://blogs.akamai.com/2018/03/memcached-fueled-13-tbps-attacks.html
Issue Tracking
https://github.com/memcached/memcached/issues/348
Third Party Advisory
https://github.com/memcached/memcached/wiki/ReleaseNotes156
Third Party Advisory
https://twitter.com/dormando/status/968579781729009664
Third Party Advisory
https://usn.ubuntu.com/3588-1/
Third Party Advisory
https://www.debian.org/security/2018/dsa-4218
Third Party Advisory
https://www.synology.com/support/security/Synology_SA_18_07
Third Party Advisory
https://access.redhat.com/errata/RHBA-2018:2140
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1593
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:1627
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:2331
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:2857
and 10 more references
62
/ 100
high-risk
Severity
26/34 · High
Exploitability
20/34 · Moderate
Exposure
16/34 · Moderate