#VU77849 Use of uninitialized resource in SoftEther VPN - CVE-2023-31192


Vulnerability identifier: #VU77849

Vulnerability risk: Medium

CVSSv4.0: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2023-31192

CWE-ID: CWE-908

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
SoftEther VPN
Server applications / Remote access servers, VPN

Vendor: SoftEther VPN Project

Description

The vulnerability allows a remote attacker to bypass certain security restrictions.

The vulnerability exists due to usage of uninitialized resources. A remote user can send a specially crafted packet to the VPN Client, trigger uninitialized usage of resources and obtain an uninitialized stack space value in the VPN Client process.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

SoftEther VPN: 4.41 9787


External links
https://jvn.jp/en/jp/JVN64316789/index.html
https://www.softether.org/9-about/News/904-SEVPN202301


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability