CVE-2023-27395
CVSS V2 None
CVSS V3 None
Description
A heap-based buffer overflow vulnerability exists in the vpnserver WpcParsePacket() functionality of SoftEther VPN 4.41-9782-beta, 5.01.9674 and 5.02. A specially crafted network packet can lead to arbitrary code execution. An attacker can perform a man-in-the-middle attack to trigger this vulnerability.
Overview
- CVE ID
- CVE-2023-27395
- Assigner
- talos
- Vulnerability Status
- PUBLISHED
- Published Version
- 2023-10-12T15:27:54.988Z
- Last Modified Date
- 2023-10-12T17:00:09.356Z
Weakness Enumerations
References
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-27395 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27395 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-25 01:35:45 | Added to TrackCVE |