Vulnerability identifier: #VU77849
Vulnerability risk: Medium
CVSSv4.0: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID:
CWE-ID:
CWE-908
Exploitation vector: Network
Exploit availability: No
Vulnerable software:
SoftEther VPN
Server applications /
Remote access servers, VPN
Vendor: SoftEther VPN Project
Description
The vulnerability allows a remote attacker to bypass certain security restrictions.
The vulnerability exists due to usage of uninitialized resources. A remote user can send a specially crafted packet to the VPN Client, trigger uninitialized usage of resources and obtain an uninitialized stack space value in the VPN Client process.
Mitigation
Install updates from vendor's website.
Vulnerable software versions
SoftEther VPN: 4.41 9787
External links
https://jvn.jp/en/jp/JVN64316789/index.html
https://www.softether.org/9-about/News/904-SEVPN202301
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.