Sliver is a command and control framework that uses a custom Wireguard netstack. In versions 1.5.43 and earlier, and in development version 1.6.0-dev, the netstack does not limit traffic between Wireguard clients. This allows clients to communicate with each other unrestrictedly, potentially enabling leaked or recovered keypairs to be used to attack operators or allowing port forwardings to be accessible from other implants.
Metrics
Affected Vendors & Products
References
History
Wed, 29 Oct 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 29 Oct 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bishopfox
Bishopfox sliver |
|
| Vendors & Products |
Bishopfox
Bishopfox sliver |
Tue, 28 Oct 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Sliver is a command and control framework that uses a custom Wireguard netstack. In versions 1.5.43 and earlier, and in development version 1.6.0-dev, the netstack does not limit traffic between Wireguard clients. This allows clients to communicate with each other unrestrictedly, potentially enabling leaked or recovered keypairs to be used to attack operators or allowing port forwardings to be accessible from other implants. | |
| Title | Sliver does not restricted traffic between Wireguard clients. | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-10-28T19:29:16.147Z
Updated: 2025-10-29T17:43:54.102Z
Reserved: 2025-02-18T16:44:48.764Z
Link: CVE-2025-27093
Updated: 2025-10-29T17:43:42.804Z
Status : Awaiting Analysis
Published: 2025-10-28T20:15:47.897
Modified: 2025-10-30T15:05:32.197
Link: CVE-2025-27093
No data.