5.5
CVE-2023-32275
- EPSS 0.39%
- Veröffentlicht 12.10.2023 16:15:11
- Zuletzt bearbeitet 04.11.2025 20:16:27
- Quelle talos-cna@cisco.com
- CVE-Watchlists
- Unerledigt
An information disclosure vulnerability exists in the CtEnumCa() functionality of SoftEther VPN 4.41-9782-beta and 5.01.9674. Specially crafted network packets can lead to a disclosure of sensitive information. An attacker can send packets to trigger this vulnerability.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.39% | 0.301 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.4 | 0.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
|
| talos-cna@cisco.com | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-201 Insertion of Sensitive Information Into Sent Data
The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.
CWE-668 Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
https://www.softether.org/9-about/News/904-SEVPN202301
https://talosintelligence.com/vulnerability_reports/TALOS-2023-1753
https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1753