Use of uninitialized resource in SoftEther VPN - CVE-2023-31192
Published: July 3, 2023
Vulnerability identifier: #VU77849
CSH Severity: Medium
CVSS v4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-31192
CWE-ID: CWE-908
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass certain security restrictions.
The vulnerability exists due to usage of uninitialized resources. A remote user can send a specially crafted packet to the VPN Client, trigger uninitialized usage of resources and obtain an uninitialized stack space value in the VPN Client process.
Affected software
SoftEther VPN
How to mitigate CVE-2023-31192
Install updates from vendor's website.
SoftEther VPN - update to 4.42 9798