PT-2025-7625 · Sliver · Sliver
Chebuya
·
Published
2025-02-19
·
Updated
2025-03-13
·
CVE-2025-27090
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Sliver versions 1.5.26 through 1.5.42
Description
The reverse port forwarding in Sliver Teamserver allows the implant to open a reverse tunnel on the Sliver Teamserver without verifying if the operator instructed the implant to do so. This issue can lead to the exposure of the server's IP address to a third party.
Recommendations
For Sliver versions 1.5.26 through 1.5.42, upgrade to version 1.5.43 to address the issue.
As a temporary workaround, consider disabling the reverse port forwarding feature in the Sliver Teamserver until a patch is available.
Restrict access to the Sliver Teamserver to minimize the risk of exploitation.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sliver