CVE-2025-27093 PUBLISHED CVSS 6.300000190734863 MEDIUM

Sliver is a command and control framework that uses a custom Wireguard netstack. In versions 1.5.43 and earlier, and in development version 1.6.0-dev, the netstack does not limit traffic between Wireguard clients. This allows clients to communicate with each other unrestrictedly, potentially enabling leaked or recovered keypairs to be used to attack operators or allowing port forwardings to be accessible from other implants.

EPSS 0.06% · 18.3th percentile

Risk Scores

CVSS v3.1
6.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
EPSS Score
0.06%
18.3th percentile

Affected Products

VendorProductVersions
github.combishopfox/sliver0
github.comBishopFox/sliver0
BishopFoxsliver<= 1.5.43

Timeline

References

Open in Interactive Console →