Vulnerability record · CVE-2018-1000115 · published 5 March 2018
CVE-2018-1000115: Memcached UDP amplification enables denial of service
MMemcached · Memcached
Memcached 1.5.5 exposes UDP support on port 11211 that allows insufficient control of network message volume, letting a small spoofed request trigger a very large response. Reported amplification factors reach roughly 1:50,000, making this a potent reflection and amplification vector for volumetric denial of service. The flaw is fixed in 1.5.6 by disabling UDP by default.
Description
Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDP support of the memcached server that can result in denial of service via network flood (traffic amplification of 1:50,000 has been reported by reliable sources). This attack appear to be exploitable via network connectivity to port 11211 UDP. This vulnerability appears to have been fixed in 1.5.6 due to the disabling of the UDP protocol by default.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityHigh CVSS (7.5) and very high EPSS with public exploits, but impact is limited to denial of service and the fix is a straightforward upgrade or disabling UDP.
What it is
Memcached 1.5.5 exposes UDP support on port 11211 that allows insufficient control of network message volume, letting a small spoofed request trigger a very large response. Reported amplification factors reach roughly 1:50,000, making this a potent reflection and amplification vector for volumetric denial of service. The flaw is fixed in 1.5.6 by disabling UDP by default.
Impact
An attacker can direct large floods of amplified traffic at a victim, exhausting bandwidth and causing denial of service. The memcached host itself is abused as a reflector; there is no confidentiality or integrity impact.
Attack surface
Reachable over the network via UDP port 11211 with no authentication and no user interaction, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any internet-exposed memcached instance with UDP enabled is a candidate reflector.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.88114, 99.759th percentile) and public Exploit-DB entries exist, indicating mature, widely available exploitation tooling.
What to do
- Upgrade memcached to 1.5.6 or later, which disables UDP by default; apply vendor errata for Red Hat, Ubuntu, Debian and Synology packages.
- If UDP is not required, disable it explicitly and bind memcached to localhost or trusted interfaces only.
- Block or rate-limit inbound UDP/11211 at the network edge and prevent spoofed-source UDP from leaving your network.
- Firewall memcached instances from the public internet; restrict access to application hosts that need it.
- Monitor for abnormal outbound UDP traffic volumes from memcached hosts.
Detection
- Alert on inbound UDP traffic to port 11211 from external or unexpected sources.
- Baseline and monitor outbound UDP packet and byte rates from memcached hosts for amplification spikes.
- Search logs and configuration management for memcached versions below 1.5.6 or instances with UDP enabled.
- Correlate large asymmetric UDP flows with memcached hosts to identify reflector participation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2018-1000115 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-1000115), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.