Skip to content
COOEY

EXPOSURES › CVE-2022-0543

CVE-2022-0543

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-28 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-0543 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 75/100 rceexploited-in-wildunpatched

A Debian-specific Redis server flaw allowed remote code execution via a Lua sandbox escape.

The Debian-specific Redis server contained a Lua sandbox escape vulnerability that enabled remote code execution. This is a critical failure for DIB organizations because it allows attackers to execute arbitrary commands on the server, leading to potential data breaches, system compromise, and compliance violations. Organizations must ensure their Redis deployments are patched and avoid relying on Debian-specific configurations that may introduce unpatched vulnerabilities.

Shame score — The vulnerability was actively exploited in the wild (KEV list) and enabled remote code execution, representing a severe, avoidable failure in securing a widely used database server.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Redis is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.