Vulnerability record · CVE-2017-5637 · published 10 October 2017
CVE-2017-5637: Apache ZooKeeper unauthenticated four-letter commands cause CPU exhaustion
Apache · Zookeeper
Apache ZooKeeper exposes the four-letter word commands "wchp" and "wchc", which are CPU intensive and lack authentication. An attacker can abuse them to spike server CPU utilization so the server cannot serve legitimate client requests. The issue affects ZooKeeper through 3.4.9 and 3.5.2, and is fixed in 3.4.10, 3.5.3 and later.
Description
Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if abused, which leads to the server unable to serve legitimate client requests. Apache ZooKeeper thru version 3.4.9 and 3.5.2 suffer from this issue, fixed in 3.4.10, 3.5.3, and later.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityNetwork-reachable, unauthenticated denial of service with a CVSS base score of 7.5 and very high EPSS probability, though not listed in KEV.
What it is
Apache ZooKeeper exposes the four-letter word commands "wchp" and "wchc", which are CPU intensive and lack authentication. An attacker can abuse them to spike server CPU utilization so the server cannot serve legitimate client requests. The issue affects ZooKeeper through 3.4.9 and 3.5.2, and is fixed in 3.4.10, 3.5.3 and later.
Impact
An attacker can degrade or deny ZooKeeper service availability by driving CPU consumption, disrupting coordination for dependent clients. There is no confidentiality or integrity impact per the CVSS vector.
Attack surface
Reachable over the network via the ZooKeeper client port with no authentication and no user interaction, as reflected in the CVSS vector AV:N/AC:L/PR:N/UI:N. The four-letter command interface is the specific entry point.
Exploitation
Not listed in CISA KEV and no public exploit references are tagged in the record, but EPSS is very high at 0.73064 (99.4th percentile), indicating elevated likelihood of attempted exploitation.
What to do
- Upgrade Apache ZooKeeper to 3.4.10, 3.5.3 or later, which fixes the issue.
- Apply vendor errata for packaged deployments (Debian DSA-3871, Red Hat RHSA-2017:2477, RHSA-2017:3354, RHSA-2017:3355).
- Disable or restrict the four-letter word command interface, per the Apache JIRA mitigation guidance, so wchp/wchc cannot be invoked remotely.
- Restrict network access to ZooKeeper client and admin ports to trusted hosts only.
- Monitor CPU utilization on ZooKeeper nodes and alert on sustained spikes.
Detection
- Monitor ZooKeeper server CPU utilization for abnormal spikes correlated with client connections.
- Inspect ZooKeeper logs and network traffic for repeated wchp and wchc four-letter command invocations.
- Alert on connections to the four-letter command interface from untrusted or unexpected source addresses.
- Baseline normal four-letter command usage and flag deviations.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2017-5637 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-5637), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.