CVE Vulnerabilities

CVE-2019-16110

Published: Nov 14, 2019 | Modified: Nov 21, 2024
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The network protocol of Blade Shadow though 2.13.3 allows remote attackers to take control of a Shadow instance and execute arbitrary code by only knowing the victims IP address, because packet data can be injected into the unencrypted UDP packet stream.

Affected Software

NameVendorStart VersionEnd Version
ShadowBlade-group*2.13.3 (including)

References