CVE-2011-10020
Kaillera 0.86 Server DoS via Malformed UDP Packet
Vexday Risk Score
36Atención
Decisión SSVC (CISA)
Attend
PoC disponible → seguir de cerca
CVSS 8.7EPSS 0.9%KEV nãoPoC —Nuclei —Metasploit simPatch —
Ciclo de vida
02 jul 2011Exploit Metasploit disponible
20 ago 2025Publicada en NVD
Recomendación: Planificar corrección próxima — ya existe PoC pública.
Kaillera Server version 0.86 is vulnerable to a denial-of-service condition triggered by sending a malformed UDP packet after the initial handshake. Once a client sends a valid HELLO0.83 packet and receives a response, any subsequent malformed packet causes the server to crash and become unresponsive. This flaw stems from improper input validation in the server’s UDP packet handler, allowing unauthenticated remote attackers to disrupt service availability.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Productos afectados
Kaillera Project · Server