PT-2019-14516 · Shadow · Blade Shadow
Publicado
2019-11-14
·
Atualizado
2020-08-24
·
CVE-2019-16110
CVSS v3.1
8.1
Alta
| Vetor | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Blade Shadow versions through 2.13.3
Description
The issue allows remote attackers to take control of a Shadow instance and execute arbitrary code by only knowing the victim's IP address. This is possible because packet data can be injected into the unencrypted UDP packet stream.
Recommendations
For versions through 2.13.3, update to a version that addresses this issue to prevent remote attackers from executing arbitrary code.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Blade Shadow