CVE-2023-31192
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Oct 12, 2023
Updated: Oct 18, 2023
CWE ID 908
CWE ID 457
Summary
CVE-2023-31192 is an information disclosure vulnerability affecting SoftEther VPN 5.01.9674. The ClientConnect() functionality is the target, which can be exploited by sending a crafted network packet. If successful, sensitive information is disclosed, potentially enabling a man-in-the-middle attack. This security flaw poses a significant risk to data confidentiality and should be addressed promptly by updating to a patched version.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- SoftEther VPN