PT-2023-19058 · Softether · Softether Vpn

Lilith >_>

·

Published

2023-10-12

·

Updated

2023-10-18

·

CVE-2023-23581

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions SoftEther VPN versions 5.01.9674 through 5.02
Description A denial-of-service issue exists in the vpnserver EnSafeHttpHeaderValueStr functionality. It can be triggered by a specially crafted network packet, leading to denial of service.
Recommendations For versions 5.01.9674 through 5.02, consider disabling the EnSafeHttpHeaderValueStr functionality in the vpnserver as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2023-23581

Affected Products

Softether Vpn