Vulnerabilities
Vulnerable Software
Softether:  >> Vpn  >> 5.02.5187  Security Vulnerabilities
SoftEther VPN 5.02.5187 is vulnerable to Buffer Overflow in the Command.c file via the PtMakeCert and PtMakeCert2048 functions. NOTE: the Supplier disputes this because the behavior only allows a user to attack himself by typing a long string on a command line.
CVSS Score
9.8
EPSS Score
0.001
Published
2025-03-12
Memory Leak vulnerability in SoftEtherVPN 5.02.5187 allows an attacker to cause a denial of service via the UnixMemoryAlloc function. NOTE: the Supplier disputes this because the behavior is limited to a single allocation of a few hundred bytes with a command-line tool.
CVSS Score
5.6
EPSS Score
0.001
Published
2025-03-12
SoftEther VPN 5.02.5187 is vulnerable to Buffer Overflow in Internat.c via the UniToStrForSingleChars function. NOTE: the Supplier disputes this because the behavior only enables a local user to attack himself through the UI,
CVSS Score
9.8
EPSS Score
0.001
Published
2025-03-12
SoftEtherVPN 5.02.5187 is vulnerable to Use after Free in the Command.c file via the CheckNetworkAcceptThread function. NOTE: the Supplier disputes this because the use-after-free is not in the VPN software, but is instead in a separate tool that has no untrusted input and runs under the user's own privileges (it is a stress-testing tool for a networking stack).
CVSS Score
9.8
EPSS Score
0.001
Published
2025-03-12


Contact Us

Shodan ® - All rights reserved