Sliver is an open source cross-platform adversary emulation/red team framework, it can be used by organizations of all sizes to perform security testing. The reverse port forwarding in sliver teamserver allows the implant to open a reverse tunnel on the sliver teamserver without verifying if the operator instructed the implant to do so. The only impact that has been shown is the exposure of the server's IP address to a third party. This issue has been addressed in version 1.5.43 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
History

Thu, 27 Feb 2025 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Bishopfox
Bishopfox sliver
CPEs cpe:2.3:a:bishopfox:sliver:*:*:*:*:*:*:*:*
Vendors & Products Bishopfox
Bishopfox sliver
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Wed, 19 Feb 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Feb 2025 21:30:00 +0000

Type Values Removed Values Added
Description Sliver is an open source cross-platform adversary emulation/red team framework, it can be used by organizations of all sizes to perform security testing. The reverse port forwarding in sliver teamserver allows the implant to open a reverse tunnel on the sliver teamserver without verifying if the operator instructed the implant to do so. The only impact that has been shown is the exposure of the server's IP address to a third party. This issue has been addressed in version 1.5.43 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
Title Server-Side Request Forgery (SSRF) in sliver teamserver
Weaknesses CWE-918
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-02-19T21:37:35.320Z

Reserved: 2025-02-18T16:44:48.764Z

Link: CVE-2025-27090

cve-icon Vulnrichment

Updated: 2025-02-19T21:37:27.852Z

cve-icon NVD

Status : Analyzed

Published: 2025-02-19T22:15:24.247

Modified: 2025-02-27T20:18:12.583

Link: CVE-2025-27090

cve-icon Redhat

No data.