Vulnerabilities > CVE-2023-22308 - Integer Underflow (Wrap or Wraparound) vulnerability in Softether VPN 5.01.9674/5.02

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
softether
CWE-191

Summary

An integer underflow vulnerability exists in the vpnserver OvsProcessData functionality of SoftEther VPN 5.01.9674 and 5.02. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.

Vulnerable Configurations

Part Description Count
Application
Softether
2

Common Weakness Enumeration (CWE)