CVE-2025-27090 Details
Description
Sliver is an open source cross-platform adversary emulation/red team framework, it can be used by organizations of all sizes to perform security testing. The reverse port forwarding in sliver teamserver allows the implant to open a reverse tunnel on the sliver teamserver without verifying if the operator instructed the implant to do so. The only impact that has been shown is the exposure of the server's IP address to a third party. This issue has been addressed in version 1.5.43 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
A vulnerability in the Sliver teamserver's reverse port forwarding feature allows an implant to establish a reverse tunnel without proper verification from the operator. This issue, present in Sliver teamserver versions 1.5.26 to 1.5.42, has been addressed in version 1.5.43. The vulnerability primarily exposes the server's IP address to third parties, with potential for more significant impacts, such as server-side request forgery, according to the vulnerability reporter.
Users are advised to upgrade to Sliver teamserver version 1.5.43 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 19, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| bishopfox sliver | >= 1.5.26, < 1.5.43 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 27, 2025 | Initial Analysis | [email protected] |
| Feb 19, 2025 | New CVE Received | [email protected] |