CVE-2013-7239Improper Authentication in Memcached

Severity
4.8MEDIUMNVD
EPSS
0.3%
top 46.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 13
Latest updateMay 14

Description

memcached before 1.4.17 allows remote attackers to bypass authentication by sending an invalid request with SASL credentials, then sending another request with incorrect SASL credentials.

CVSS vector

AV:A/AC:L/C:P/I:P/A:NExploitability: 6.5 | Impact: 4.9

Affected Packages3 packages

debiandebian/memcached< memcached 1.4.13-0.3 (bookworm)
Debianmemcached/memcached< 1.4.13-0.3+3
NVDmemcached/memcached1.4.16+16

Patches

🔴Vulnerability Details

2
GHSA
GHSA-v5qw-pp2p-cvpr: memcached before 12022-05-14
OSV
CVE-2013-7239: memcached before 12014-01-13

📋Vendor Advisories

3
Ubuntu
Memcached vulnerabilities2014-01-13
Red Hat
memcached: SASL authentication allows wrong credentials to access memcache2013-04-19
Debian
CVE-2013-7239: memcached - memcached before 1.4.17 allows remote attackers to bypass authentication by send...2013

💬Community

1
Bugzilla
CVE-2013-7239 memcached: SASL authentication allows wrong credentials to access memcache2013-12-30