PT-2025-5636 · Tshock · Tshock
Published
2025-02-03
·
Updated
2025-02-03
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions:
TShock (affected versions not specified)
Description:
This issue allows malicious clients to connect to a server without completing the connection handshake, occupying a player slot, and receiving data from the server, even if they are banned. This can lead to harassment, observation, and utilization of server resources. The problem arises because TShock checks for bans upon the Request World Data packet, which a malicious client can choose not to send, still allowing them to join the server and chat. Other clients will not be notified of their join/leave but can see them on the player list, potentially leading to chat spam and spying on packets of players within the server.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tshock