VDB
CVE-2025-27093
CVE-2025-27093
PUBLISHED
CVSS 6.300000190734863 MEDIUM
Sliver is a command and control framework that uses a custom Wireguard netstack. In versions 1.5.43 and earlier, and in development version 1.6.0-dev, the netstack does not limit traffic between Wireguard clients. This allows clients to communicate with each other unrestrictedly, potentially enabling leaked or recovered keypairs to be used to attack operators or allowing port forwardings to be accessible from other implants.
EPSS 0.04% · 11.8th percentile
Risk Scores
CVSS 3.1
6.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
EPSS Score
0.04%
11.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| github.com | bishopfox/sliver | 0 |
| github.com | BishopFox/sliver | 0 |
| BishopFox | sliver | * |
Exploit Intelligence
- CIRCL seen: CVE-2025-27093 (circl-sighting)
- CIRCL seen: CVE-2025-27093 (circl-sighting)
- CIRCL seen: CVE-2025-27093 (circl-sighting)
- CIRCL seen: CVE-2025-27093 (circl-sighting)
- https://github.com/BishopFox/sliver/commit/8e5c5f14506d6d60ebb3362e6b9857ab1e0d76ff (circl)
- https://github.com/BishopFox/sliver/commit/9122878cbbcae543eb8210f616550382af2065fd (circl)
- https://github.com/BishopFox/sliver/security/advisories/GHSA-q8j9-34qf-7vq7 (cve.org)
Timeline
- Jan 21, 1970 Security Advisory
- Oct 28, 2025 CVE Published
- Oct 28, 2025 Coalition ESS Score
- Oct 29, 2025 EPSS Score
- Nov 4, 2025 EPSS Score
- Nov 5, 2025 CVE Updated
- Nov 9, 2025 EPSS Score
- Nov 15, 2025 EPSS Score
- Nov 20, 2025 EPSS Score
- Nov 21, 2025 PoC Published
- Nov 21, 2025 PoC Published
- Nov 22, 2025 PoC Published
References
- https://github.com/BishopFox/sliver/security/advisories/GHSA-q8j9-34qf-7vq7 url
- https://github.com/BishopFox/sliver/commit/8e5c5f14506d6d60ebb3362e6b9857ab1e0d76ff url
- https://github.com/BishopFox/sliver/commit/9122878cbbcae543eb8210f616550382af2065fd url
- https://nvd.nist.gov/vuln/detail/CVE-2025-27093 advisory
- https://github.com/BishopFox/sliver package
- https://pkg.go.dev/vuln/GO-2025-4079 url