CVE-2025-27093
Last modified
CVE-2025-27093 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. Sliver is a command and control framework that uses a custom Wireguard netstack. In versions 1.5.43 and earlier, and in development version 1.6.0-dev, the netstack does not limit traffic between Wireguard clients. EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
Sliver is a command and control framework that uses a custom Wireguard netstack. In versions 1.5.43 and earlier, and in development version 1.6.0-dev, the netstack does not limit traffic between Wireguard clients. This allows clients to communicate with each other unrestrictedly, potentially enabling leaked or recovered keypairs to be used to attack operators or allowing port forwardings to be accessible from other implants.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-27093?
How severe is CVE-2025-27093?
How do I fix CVE-2025-27093?
Are you affected by CVE-2025-27093?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
