Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2017-15924

In manager.c in ss-manager in shadowsocks-libev 3.1.0, improper parsing allows command injection via shell metacharacters in a JSON configuration request received via 127.0.0.1 UDP traffic, related to the add_server, build_config, and construct_command_line functions.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 62.5%
CVSS Severity
CVSS v3 Score 7.8
CVSS v2 Score 7.2
Products affected by CVE-2017-15924


Contact Us

Shodan ® - All rights reserved