Use of uninitialized resource in SoftEther VPN - CVE-2023-31192

 

Use of uninitialized resource in SoftEther VPN - CVE-2023-31192

Published: July 3, 2023


Vulnerability identifier: #VU77849
CSH Severity: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2023-31192
CWE-ID: CWE-908
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
SoftEther VPN
Software vendor:
SoftEther VPN Project

Description

The vulnerability allows a remote attacker to bypass certain security restrictions.

The vulnerability exists due to usage of uninitialized resources. A remote user can send a specially crafted packet to the VPN Client, trigger uninitialized usage of resources and obtain an uninitialized stack space value in the VPN Client process.


Remediation

Install updates from vendor's website.

External links