5.3

CVE-2023-31192

Exploit
An information disclosure vulnerability exists in the ClientConnect() functionality of SoftEther VPN 5.01.9674. A specially crafted network packet can lead to a disclosure of sensitive information. An attacker can perform a man-in-the-middle attack to trigger this vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SoftetherVpn Version5.01.9674
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.81% 0.521
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.3 1.6 3.6
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
talos-cna@cisco.com 5.3 1.6 3.6
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-457 Use of Uninitialized Variable

The code uses a variable that has not been initialized, leading to unpredictable or unintended results.

CWE-908 Use of Uninitialized Resource

The product uses or accesses a resource that has not been initialized.

https://www.softether.org/9-about/News/904-SEVPN202301
Patch
Vendor Advisory
https://talosintelligence.com/vulnerability_reports/TALOS-2023-1768
Third Party Advisory
Exploit
https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1768