← volver
CVE-2026-29781

Sliver: Authenticated Nil-Pointer Dereference in Handlers

CVSS 2.1 LOWEPSS 0.5%CWE-476
Vexday Risk Score
8Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 2.1EPSS 0.5%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
07 mar 2026Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Sliver is a command and control framework that uses a custom Wireguard netstack. In versions from 1.7.3 and prior, a vulnerability exists in the Sliver C2 server's Protobuf unmarshalling logic due to a systemic lack of nil-pointer validation. By extracting valid implant credentials and omitting nested fields in a signed message, an authenticated actor can trigger an unhandled runtime panic. Because the mTLS, WireGuard, and DNS transport layers lack the panic recovery middleware present in the HTTP transport, this results in a global process termination. While requiring post-authentication access (a captured implant), this flaw effectively acts as an infrastructure "kill-switch," instantly severing all active sessions across the entire fleet and requiring a manual server restart to restore operations. At time of publication, there are no publicly available patches.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
Productos afectados
BishopFox · sliver

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →