Vulnerabilities > CVE-2023-32634 - Unspecified vulnerability in Softether VPN 4.419782/5.01.9674

047910
CVSS 7.4 - HIGH
Attack vector
LOCAL
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
local
high complexity
softether

Summary

An authentication bypass vulnerability exists in the CiRpcServerThread() functionality of SoftEther VPN 5.01.9674 and 4.41-9782-beta. An attacker can perform a local man-in-the-middle attack to trigger this vulnerability.

Vulnerable Configurations

Part Description Count
Application
Softether
2