Vulnerability Description
The network protocol of Blade Shadow though 2.13.3 allows remote attackers to take control of a Shadow instance and execute arbitrary code by only knowing the victim's IP address, because packet data can be injected into the unencrypted UDP packet stream.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Blade-Group | Shadow | <= 2.13.3 |
References
- https://sigint.sh/#/cve-2019-16110Third Party Advisory
- https://sigint.sh/#/cve-2019-16110Third Party Advisory
FAQ
What is CVE-2019-16110?
CVE-2019-16110 is a vulnerability with a CVSS score of 8.1 (HIGH). The network protocol of Blade Shadow though 2.13.3 allows remote attackers to take control of a Shadow instance and execute arbitrary code by only knowing the victim's IP address, because packet data ...
How severe is CVE-2019-16110?
CVE-2019-16110 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-16110?
Check the references section above for vendor advisories and patch information. Affected products include: Blade-Group Shadow.