CVE Vulnerabilities

CVE-2023-27516

Insecure Default Variable Initialization

Published: Oct 12, 2023 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An authentication bypass vulnerability exists in the CiRpcAccepted() functionality of SoftEther VPN 4.41-9782-beta and 5.01.9674. A specially crafted network packet can lead to unauthorized access. An attacker can send a network request to trigger this vulnerability.

Weakness

The product, by default, initializes an internal variable with an insecure or less secure value than is possible.

Affected Software

Name Vendor Start Version End Version
Vpn Softether 4.41-9782-beta (including) 4.41-9782-beta (including)
Vpn Softether 5.01.9674 (including) 5.01.9674 (including)

Potential Mitigations

References