Network amplification in memcached - CVE-2018-1000115
Published: March 21, 2018 / Updated: January 26, 2021
Vulnerability identifier: #VU11194
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1000115
CWE-ID: CWE-406
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote unauthenticated attacker to conduct DDoS amplification attack against the target system.
The weakness exists due to insufficient control of network message volume. A remote attacker can scan for affected, insecure Memcached servers via UDP port 11211,spoof UDP packets, send a specially crafted request, trigger a response and conduct DDoS amplification attack.
The weakness exists due to insufficient control of network message volume. A remote attacker can scan for affected, insecure Memcached servers via UDP port 11211,spoof UDP packets, send a specially crafted request, trigger a response and conduct DDoS amplification attack.
Affected software
memcached
Debian Linux
Ubuntu
Fedora
memcached (Alpine package)
memcached
Red Hat OpenStack
Red Hat OpenStack for IBM Power
Debian Linux
Ubuntu
Fedora
memcached (Alpine package)
memcached
Red Hat OpenStack
Red Hat OpenStack for IBM Power
How to mitigate CVE-2018-1000115
Update to version 1.5.6.
memcached (Alpine package) - update to 1.4.33-r2
memcached - addressed in versions 1.4.39-2.fc26, 1.5.7-1.fc27
memcached - addressed in versions 1.4.39-2.fc26, 1.5.7-1.fc27