CVE-2023-31192
CVE-2023-31192 is a medium-severity vulnerability in Softether Vpn with a CVSS 3.x base score of 5.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-908.
Key facts
- Severity: Medium (CVSS 3.x base score 5.3)
- EPSS exploit prediction: 1% (59th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-908
- Affected product: Softether Vpn
- Published:
- Last modified:
Description
An information disclosure vulnerability exists in the ClientConnect() functionality of SoftEther VPN 5.01.9674. A specially crafted network packet can lead to a disclosure of sensitive information. An attacker can perform a man-in-the-middle attack to trigger this vulnerability.
Frequently asked questions
- What is CVE-2023-31192?
- An information disclosure vulnerability exists in the ClientConnect() functionality of SoftEther VPN 5.01.9674. A specially crafted network packet can lead to a disclosure of sensitive information. An attacker can perform a man-in-the-middle attack to trigger this vulnerability.
- How severe is CVE-2023-31192?
- CVE-2023-31192 has a CVSS 3.x base score of 5.3, rated medium severity. It is exploitable over network with high attack complexity, requires low privileges and no user interaction. Impact on confidentiality is high, integrity none, and availability none.
- Is CVE-2023-31192 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (59th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2023-31192?
- CVE-2023-31192 affects Softether Vpn. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2023-31192?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2023-31192 published?
- CVE-2023-31192 was published on 2023-10-12 and last updated on 2026-06-17.
References
- https://talosintelligence.com/vulnerability_reports/TALOS-2023-1768
- https://www.softether.org/9-about/News/904-SEVPN202301
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1768
Affected products (1)
- cpe:2.3:a:softether:vpn:5.01.9674:*:*:*:*:*:*:*
More vulnerabilities in Softether Vpn
- CVE-2025-25568 — Critical (CVSS 9.8): SoftEtherVPN 5.02.5187 is vulnerable to Use after Free in the Command.c file via the CheckNetworkAcceptThread function.…
- CVE-2025-25567 — Critical (CVSS 9.8): SoftEther VPN 5.02.5187 is vulnerable to Buffer Overflow in Internat.c via the UniToStrForSingleChars function. NOTE:…
- CVE-2025-25565 — Critical (CVSS 9.8): SoftEther VPN 5.02.5187 is vulnerable to Buffer Overflow in the Command.c file via the PtMakeCert and PtMakeCert2048…
- CVE-2023-27395 — Critical (CVSS 9.0): A heap-based buffer overflow vulnerability exists in the vpnserver WpcParsePacket() functionality of SoftEther VPN…
- CVE-2023-32634 — High (CVSS 7.8): An authentication bypass vulnerability exists in the CiRpcServerThread() functionality of SoftEther VPN 5.01.9674 and…
- CVE-2023-25774 — High (CVSS 7.5): A denial-of-service vulnerability exists in the vpnserver ConnectionAccept() functionality of SoftEther VPN 5.02. A set…
All CVEs affecting Softether Vpn →
Other CWE-908 (Use of Uninitialized Resource) vulnerabilities
- CVE-2025-38429 — Critical (CVSS 10.0): In the Linux kernel, the following vulnerability has been resolved: bus: mhi: ep: Update read pointer only after…
- CVE-2026-56190 — Critical (CVSS 9.8): Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.
- CVE-2026-52989 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec()…
- CVE-2022-50335 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: 9p: set req refcount to zero to avoid…
- CVE-2025-38737 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: cifs: Fix oops due to uninitialised variable Fix…
- CVE-2025-38472 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack: fix crash due to removal…
Browse all CWE-908 (Use of Uninitialized Resource) vulnerabilities →