An information disclosure vulnerability exists in the CtEnumCa() functionality of SoftEther VPN 4.41-9782-beta and 5.01.9674. Specially crafted network packets can lead to a disclosure of sensitive information. An attacker can send packets to trigger this vulnerability.
The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
Link | Tags |
---|---|
https://talosintelligence.com/vulnerability_reports/TALOS-2023-1753 | third party advisory exploit |
https://www.softether.org/9-about/News/904-SEVPN202301 | vendor advisory |