Vulnerabilities > CVE-2023-32275 - Exposure of Resource to Wrong Sphere vulnerability in Softether VPN 4.419782/5.01.9674

047910
CVSS 4.4 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
HIGH
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
local
low complexity
softether
CWE-668

Summary

An information disclosure vulnerability exists in the CtEnumCa() functionality of SoftEther VPN 4.41-9782-beta and 5.01.9674. Specially crafted network packets can lead to a disclosure of sensitive information. An attacker can send packets to trigger this vulnerability.

Vulnerable Configurations

Part Description Count
Application
Softether
2

Common Weakness Enumeration (CWE)