CVE Vulnerabilities

CVE-2019-16110

Published: Nov 14, 2019 | Modified: Aug 24, 2020
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The network protocol of Blade Shadow though 2.13.3 allows remote attackers to take control of a Shadow instance and execute arbitrary code by only knowing the victims IP address, because packet data can be injected into the unencrypted UDP packet stream.

Affected Software

Name Vendor Start Version End Version
Shadow Blade-group * 2.13.3 (including)

References