Record summary

CVE-2011-10020 has a selected CVSS score of 8.7 (high); EIP currently links 2 catalogued exploits.

Description

Kaillera Server version 0.86 is vulnerable to a denial-of-service condition triggered by sending a malformed UDP packet after the initial handshake. Once a client sends a valid HELLO0.83 packet and receives a response, any subsequent malformed packet causes the server to crash and become unresponsive. This flaw stems from improper input validation in the server’s UDP packet handler, allowing unauthenticated remote attackers to disrupt service availability.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
2

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 22, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected

CVE ListThrough 0.86affected

Proofs of concept

2

Catalogued exploits

ExploitDBKaillera - Multiple Clients Buffer Overflow VulnerabilitiesExploitDB exploitby Sil3nt_Dre4mNot analyzed1 file
ExploitDB

PoC details
MetasploitKaillera 0.86 Server Denial of ServiceMetasploit auxiliary PoCby Sil3nt_Dre4mNot analyzed1 file

Ruby

Metasploit

PoC details

References

5