CVE-2008-6737

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
21/04/2009
Last modified:
09/04/2025

Description

Crysis 1.21 and earlier allows remote attackers to obtain sensitive player information such as real IP addresses by sending a keyexchange packet without a previous join packet, which causes Crysis to send a disconnect packet that includes unrelated log information.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ea:crysis:*:*:*:*:*:*:*:* 1.21 (including)
cpe:2.3:a:ea:crysis:1.1:*:*:*:*:*:*:*
cpe:2.3:a:ea:crysis:1.2:*:*:*:*:*:*:*