7.8
CVE-2023-32634
- EPSS 0.43%
- Veröffentlicht 12.10.2023 16:15:11
- Zuletzt bearbeitet 04.11.2025 20:16:28
- Quelle talos-cna@cisco.com
- CVE-Watchlists
- Unerledigt
An authentication bypass vulnerability exists in the CiRpcServerThread() functionality of SoftEther VPN 5.01.9674 and 4.41-9782-beta. An attacker can perform a local man-in-the-middle attack to trigger this vulnerability.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.43% | 0.34 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.4 | 1.4 | 5.9 |
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| talos-cna@cisco.com | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-300 Channel Accessible by Non-Endpoint
The product does not adequately verify the identity of actors at both ends of a communication channel, or does not adequately ensure the integrity of the channel, in a way that allows the channel to be accessed or influenced by an actor that is not an endpoint.
https://www.softether.org/9-about/News/904-SEVPN202301
https://talosintelligence.com/vulnerability_reports/TALOS-2023-1755
https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1755