CVE-2018-1000115

UnknownEPSS 88.64%

Last modified

CVE-2018-1000115 is a vulnerability of currently unknown severity. Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDP support of the memcached server that can result in denial of service via network flood (traffic amplification of 1:50,000 has been reported by reliable sources). This attack appear to be exploitable via network connectivity to port 11211 UDP. EPSS estimates a 88.64% chance of exploitation in the next 30 days.

Description

Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDP support of the memcached server that can result in denial of service via network flood (traffic amplification of 1:50,000 has been reported by reliable sources). This attack appear to be exploitable via network connectivity to port 11211 UDP. This vulnerability appears to have been fixed in 1.5.6 due to the disabling of the UDP protocol by default.

Metrics

EPSS Probability
88.64%

99.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
MemcachedMemcached1.5.5
CanonicalUbuntu Linux14.04
CanonicalUbuntu Linux16.04
CanonicalUbuntu Linux17.10
DebianDebian Linux8.0
DebianDebian Linux9.0
RedhatOpenstack8
RedhatOpenstack9
RedhatOpenstack10
RedhatOpenstack11
RedhatOpenstack12

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2018-1000115?
Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDP support of the memcached server that can result in denial of service via network flood (traffic amplification of 1:50,000 has been reported by reliable sources). This attack appear to be exploitable via network connectivity to port 11211 UDP. This vulnerability appears to have been fixed in 1.5.6 due to the disabling of the UDP protocol by default.
How severe is CVE-2018-1000115?
Severity scoring for CVE-2018-1000115 is pending analysis. The EPSS model estimates a 88.64% probability of exploitation in the next 30 days.
How do I fix CVE-2018-1000115?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2018-1000115?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST