Use of uninitialized resource in SoftEther VPN - CVE-2023-31192

 

Use of uninitialized resource in SoftEther VPN - CVE-2023-31192

Published: July 3, 2023


Vulnerability identifier: #VU77849
CSH Severity: Medium
CVSS v4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-31192
CWE-ID: CWE-908
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass certain security restrictions.

The vulnerability exists due to usage of uninitialized resources. A remote user can send a specially crafted packet to the VPN Client, trigger uninitialized usage of resources and obtain an uninitialized stack space value in the VPN Client process.


Affected software

SoftEther VPN

How to mitigate CVE-2023-31192

Install updates from vendor's website.

SoftEther VPN - update to 4.42 9798

External References

Related Security Bulletins