CVE-2020-22570Command Injection in Memcached

CWE-77Command Injection6 documents6 sources
Severity
7.5HIGHNVD
EPSS
2.1%
top 16.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 22

Description

Memcached 1.6.0 before 1.6.3 allows remote attackers to cause a denial of service (daemon crash) via a crafted meta command.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

debiandebian/memcached< memcached 1.6.3-1 (bookworm)
NVDmemcached/memcached1.6.01.6.3
Debianmemcached/memcached< 1.6.3-1+3

🔴Vulnerability Details

2
OSV
CVE-2020-22570: Memcached 12023-08-22
GHSA
GHSA-fq43-fxrw-vjrh: Memcached 12023-08-22

📋Vendor Advisories

2
Red Hat
memcached: NULL pointer dereference in process_mget_command function in memcached.c2023-08-22
Debian
CVE-2020-22570: memcached - Memcached 1.6.0 before 1.6.3 allows remote attackers to cause a denial of servic...2020

🕵️Threat Intelligence

1
Wiz
CVE-2026-24809 Impact, Exploitability, and Mitigation Steps | Wiz