Impact
The vulnerability arises from an out-of-bounds read in the try_read_command_asciiauth function within memcached's mcmc Tokenizer logic. An attacker can craft a malformed authentication request that causes the server to read memory beyond intended bounds, potentially exposing sensitive data or causing a denial of service. This weakness can compromise confidentiality and availability and is identified as an out-of-bounds read flaw.
Affected Systems
Memcached versions 1.6.41, 1.6.42, and 1.6.43 are affected. The fix is incorporated in version 1.6.44 and later. Systems running these vulnerable releases, particularly those exposed to external networks, are at risk.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not currently listed in CISA's KEV catalog. Remote attackers can trigger the flaw by sending specific authentication packets, making the threat vector remote. Even though exploitation probability is low, the impact of a successful read could be significant.
OpenCVE Enrichment