CVE-2020-22570: Command Injection
Published Aug 22, 2023
·Updated
Memcached 1.6.0 before 1.6.3 allows remote attackers to cause a denial of service (daemon crash) via a crafted meta command.
Affected Software
1 affected component
Memcached Memcached>=1.6.0<1.6.3
Event History
Aug 22, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this security issue?
The vulnerability ID is CVE-2020-22570.
2
What is the severity of CVE-2020-22570?
The severity of CVE-2020-22570 is high with a severity value of 7.5.
3
What is the affected software for CVE-2020-22570?
The affected software for CVE-2020-22570 is Memcached version 1.6.0 to 1.6.3.
4
How can remote attackers exploit CVE-2020-22570?
Remote attackers can cause a denial of service (daemon crash) by sending a crafted meta command.
5
Is there a fix available for CVE-2020-22570?
Yes, the fix for CVE-2020-22570 is to upgrade to Memcached version 1.6.3 or later.