HIGH · 7.5

CVE-2018-1000115

Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDP support of the memcached server that can result in denial o...

Vulnerability Description

Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDP support of the memcached server that can result in denial of service via network flood (traffic amplification of 1:50,000 has been reported by reliable sources). This attack appear to be exploitable via network connectivity to port 11211 UDP. This vulnerability appears to have been fixed in 1.5.6 due to the disabling of the UDP protocol by default.

CVSS Score

7.5

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
MemcachedMemcached1.5.5
CanonicalUbuntu Linux14.04
DebianDebian Linux8.0
RedhatOpenstack8

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-1000115?

CVE-2018-1000115 is a vulnerability with a CVSS score of 7.5 (HIGH). Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDP support of the memcached server that can result in denial o...

How severe is CVE-2018-1000115?

CVE-2018-1000115 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-1000115?

Check the references section above for vendor advisories and patch information. Affected products include: Memcached Memcached, Canonical Ubuntu Linux, Debian Debian Linux, Redhat Openstack.