⚠ Actively exploited
Added to CISA KEV on 2022-03-28. Federal agencies required to patch by 2022-04-18. Required action: Apply updates per vendor instructions..

CVE-2022-0543Missing Authorization in Redis

Severity
10.0CRITICALNVD
CISA7.8
EPSS
94.4%
top 0.02%
CISA KEV
KEV
Added 2022-03-28
Due 2022-04-18
Exploit
Exploited in wild
Active exploitation observed
Affected products
Timeline
PublishedFeb 18
KEV addedMar 28
KEV dueApr 18
Latest updateJan 27
CISA Required Action: Apply updates per vendor instructions.

Description

It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HExploitability: 3.9 | Impact: 6.0

Affected Packages3 packages

debiandebian/redis< redis 5:6.0.16-2 (bookworm)
CVEListV5debian/redisn/a
Debianredis/redis< 5:6.0.16-1+deb11u2+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-9wpj-h5jq-88p9: It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which co2022-02-19
OSV
CVE-2022-0543: It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which co2022-02-18
VulnCheck
Debian-specific Redis Server Lua Sandbox Escape Vulnerability2022

💥Exploits & PoCs

2
Metasploit
Redis Lua Sandbox Escape
Nuclei
Redis Sandbox Escape - Remote Code Execution

🔍Detection Rules

4
Suricata
ET EXPLOIT Redis RCE Attempt (CVE-2022-0543) M22026-01-27
Suricata
ET EXPLOIT Redis RCE Attempt (CVE-2022-0543) M22022-04-04
Suricata
ET EXPLOIT Possible Redis RCE Attempt - Dynamic Importing of liblua (CVE-2022-0543)2022-04-04
Suricata
ET EXPLOIT Redis RCE Attempt (CVE-2022-0543) M12022-04-04

📋Vendor Advisories

4
CISA
Debian-specific Redis Server Lua Sandbox Escape Vulnerability2022-03-28
CISA
Microsoft Windows Privilege Escalation Vulnerability2022-03-15
Ubuntu
Redis vulnerability2022-03-08
Debian
CVE-2022-0543: redis - It was discovered, that redis, a persistent key-value database, due to a packagi...2022

🕵️Threat Intelligence

4
Bleepingcomputer
Stealthier version of P2Pinfect malware targets MIPS devices2023-12-04
Wiz
Crying Out Cloud - August Newsletter | Wiz2023-08-30
Unit42
P2PInfect: The Rusty Peer-to-Peer Self-Replicating Worm2023-07-19
Unit42
P2PInfect: The Rusty Peer-to-Peer Self-Replicating Worm2023-07-19

📄Research Papers

3
CTF
medium / README
CTF
Shared / README
CTF
Shared / README