PT-2019-14516 · Shadow · Blade Shadow
Published
2019-11-14
·
Updated
2020-08-24
·
CVE-2019-16110
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Blade Shadow versions through 2.13.3
Description
The issue allows remote attackers to take control of a Shadow instance and execute arbitrary code by only knowing the victim's IP address. This is possible because packet data can be injected into the unencrypted UDP packet stream.
Recommendations
For versions through 2.13.3, update to a version that addresses this issue to prevent remote attackers from executing arbitrary code.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Blade Shadow