CVE-2023-23581
SoftEther VPN Server vulnerability analysis and mitigation

Overview

A denial-of-service vulnerability (CVE-2023-23581) exists in the vpnserver EnSafeHttpHeaderValueStr functionality of SoftEther VPN versions 5.01.9674 and 5.02. The vulnerability was discovered by Lilith of Cisco Talos and publicly disclosed on October 12, 2023. SoftEther VPN is a multi-platform VPN project that provides both server and client code to connect over various VPN protocols, including Wireguard, PPTP, SSTP, and L2TP (Talos Report).

Technical details

The vulnerability is classified as CWE-125 (Out-of-bounds Read) and has a CVSSv3 score of 7.5 (HIGH) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. The issue occurs in the EnSafeHttpHeaderValueStr function when processing HTTP headers containing '\r' or '\n' sequences. The function's implementation causes a one-byte out-of-bounds read when copying from [index + 2] with length - index, potentially accessing the null terminator and the byte immediately after (Talos Report).

Impact

When exploited, this vulnerability can lead to a denial of service condition by causing the server to crash. This is achieved through careful heap manipulation that can cause the single byte read to access the first byte of an unmapped page or non-readable page in memory (Talos Report).

Mitigation and workarounds

The vendor released a patch on April 22, 2023, to address this vulnerability. Users should upgrade to a version newer than 5.02. The fix was implemented through a pull request on Github: https://github.com/SoftEtherVPN/SoftEtherVPN/pull/1829 (Talos Report).

Additional resources


SourceThis report was generated using AI

Related SoftEther VPN Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-25568CRITICAL9.8
  • SoftEther VPN ServerSoftEther VPN Server
  • cpe:2.3:a:softether:vpn
NoNoMar 12, 2025
CVE-2025-25567CRITICAL9.8
  • SoftEther VPN ServerSoftEther VPN Server
  • cpe:2.3:a:softether:vpn
NoNoMar 12, 2025
CVE-2025-25565CRITICAL9.8
  • SoftEther VPN ServerSoftEther VPN Server
  • cpe:2.3:a:softether:vpn
NoNoMar 12, 2025
CVE-2025-25566MEDIUM5.6
  • SoftEther VPN ServerSoftEther VPN Server
  • cpe:2.3:a:softether:vpn
NoNoMar 12, 2025
CVE-2024-38520MEDIUM5.3
  • SoftEther VPN ServerSoftEther VPN Server
  • cpe:2.3:a:softether:vpn
NoNoJun 26, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management