Vulnerabilities > CVE-2023-27516 - Insecure Default Initialization of Resource vulnerability in Softether VPN 4.419782/5.01.9674

047910
CVSS 7.8 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
local
low complexity
softether
CWE-1188

Summary

An authentication bypass vulnerability exists in the CiRpcAccepted() functionality of SoftEther VPN 4.41-9782-beta and 5.01.9674. A specially crafted network packet can lead to unauthorized access. An attacker can send a network request to trigger this vulnerability.

Vulnerable Configurations

Part Description Count
Application
Softether
2