softether records
16 published records for vendor softether.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 6.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-400 Uncontrolled Resource Consumption2
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')2
- CWE-125 Out-of-bounds Read1
- CWE-191 Integer Underflow (Wrap or Wraparound)1
- CWE-201 Insertion of Sensitive Information Into Sent Data1
- CWE-300 Channel Accessible by Non-Endpoint1
The weakness classes this vendor ships most often: where to look.
CWEAll records
16 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2025-25565No exploit | SoftEther VPN 5.02.5187 is vulnerable to Buffer Overflow in the Command.c file via the PtMakeCert and PtMakeCert2048 functions.softether · vpn · CWE-120 | Critical9.8 | — | 0.6% | Mar 12, 2025 |
39Monitor | CVE-2025-25567No exploit | SoftEther VPN 5.02.5187 is vulnerable to Buffer Overflow in Internat.c via the UniToStrForSingleChars function.softether · vpn · CWE-120 | Critical9.8 | — | 0.6% | Mar 12, 2025 |
39Monitor | CVE-2025-25568No exploit | SoftEtherVPN 5.02.5187 is vulnerable to Use after Free in the Command.c file via the CheckNetworkAcceptThread function.softether · vpn · CWE-416 | Critical9.8 | — | 0.6% | Mar 12, 2025 |
32Monitor | CVE-2023-27395No exploit | A heap-based buffer overflow vulnerability exists in the vpnserver WpcParsePacket() functionality of SoftEther VPN 4.41-9782-beta, 5.01.9674softether · vpn · CWE-122 | High8.1 | — | 1.5% | Oct 12, 2023 |
31Monitor | CVE-2023-27516No exploit | An authentication bypass vulnerability exists in the CiRpcAccepted() functionality of SoftEther VPN 4.41-9782-beta and 5.01.9674.softether · vpn · CWE-453 | High7.8 | — | 0.5% | Oct 12, 2023 |
31Monitor | CVE-2019-11868No exploit | See.sys, up to version 4.25, in SoftEther VPN Server versions 4.29 or older, allows a user to call an IOCTL specifying any kernel address tosoftether · see.sys · CWE-787 | High7.8 | — | 0.4% | Jul 29, 2019 |
30Monitor | CVE-2023-23581No exploit | A denial-of-service vulnerability exists in the vpnserver EnSafeHttpHeaderValueStr functionality of SoftEther VPN 5.01.9674 and 5.02.softether · vpn · CWE-125 | High7.5 | — | 0.8% | Oct 12, 2023 |
30Monitor | CVE-2023-25774No exploit | A denial-of-service vulnerability exists in the vpnserver ConnectionAccept() functionality of SoftEther VPN 5.02.softether · vpn · CWE-400 | High7.5 | — | 0.7% | Oct 12, 2023 |
30Monitor | CVE-2023-22308No exploit | An integer underflow vulnerability exists in the vpnserver OvsProcessData functionality of SoftEther VPN 5.01.9674 and 5.02.softether · vpn · CWE-191 | High7.5 | — | 0.7% | Oct 12, 2023 |
30Monitor | CVE-2026-39312No exploit | Pre-Auth EAP-TLS DoS on SoftEther VPN Developer Editionsoftether · softethervpn · CWE-789 | High7.5 | — | 0.7% | Apr 7, 2026 |
29Monitor | CVE-2023-32634No exploit | An authentication bypass vulnerability exists in the CiRpcServerThread() functionality of SoftEther VPN 5.01.9674 and 4.41-9782-beta.softether · vpn · CWE-300 | High7.4 | — | 0.4% | Oct 12, 2023 |
23Monitor | CVE-2023-22325No exploit | A denial of service vulnerability exists in the DCRegister DDNS_RPC_MAX_RECV_SIZE functionality of SoftEther VPN 4.41-9782-beta, 5.01.9674 asoftether · vpn · CWE-835 | Medium5.9 | — | 1.0% | Oct 12, 2023 |
22Monitor | CVE-2025-25566No exploit | Memory Leak vulnerability in SoftEtherVPN 5.02.5187 allows an attacker to cause a denial of service via the UnixMemoryAlloc function.softether · vpn · CWE-401 | Medium5.6 | — | 0.3% | Mar 12, 2025 |
21Monitor | CVE-2023-31192No exploit | An information disclosure vulnerability exists in the ClientConnect() functionality of SoftEther VPN 5.01.9674.softether · vpn · CWE-457 | Medium5.3 | — | 1.0% | Oct 12, 2023 |
21Monitor | CVE-2024-38520No exploit | SoftEther VPN with L2TP - 2.75x Amplificationsoftethervpn · softethervpn · CWE-400 | Medium5.3 | — | 0.5% | Jun 26, 2024 |
17Monitor | CVE-2023-32275No exploit | An information disclosure vulnerability exists in the CtEnumCa() functionality of SoftEther VPN 4.41-9782-beta and 5.01.9674.softether · vpn · CWE-201 | Medium4.4 | — | 0.4% | Oct 12, 2023 |
- CVE-2025-2556539Monitor
SoftEther VPN 5.02.5187 is vulnerable to Buffer Overflow in the Command.c file via the PtMakeCert and PtMakeCert2048 functions.
CriticalCVSS 9.8No exploitEPSS 1%softether · vpnMar 12, 2025
- CVE-2025-2556739Monitor
SoftEther VPN 5.02.5187 is vulnerable to Buffer Overflow in Internat.c via the UniToStrForSingleChars function.
CriticalCVSS 9.8No exploitEPSS 1%softether · vpnMar 12, 2025
- CVE-2025-2556839Monitor
SoftEtherVPN 5.02.5187 is vulnerable to Use after Free in the Command.c file via the CheckNetworkAcceptThread function.
CriticalCVSS 9.8No exploitEPSS 1%softether · vpnMar 12, 2025
- CVE-2023-2739532Monitor
A heap-based buffer overflow vulnerability exists in the vpnserver WpcParsePacket() functionality of SoftEther VPN 4.41-9782-beta, 5.01.9674
HighCVSS 8.1No exploitEPSS 2%softether · vpnOct 12, 2023
- CVE-2023-2751631Monitor
An authentication bypass vulnerability exists in the CiRpcAccepted() functionality of SoftEther VPN 4.41-9782-beta and 5.01.9674.
HighCVSS 7.8No exploitEPSS 1%softether · vpnOct 12, 2023
- CVE-2019-1186831Monitor
See.sys, up to version 4.25, in SoftEther VPN Server versions 4.29 or older, allows a user to call an IOCTL specifying any kernel address to
HighCVSS 7.8No exploitEPSS 0%softether · see.sysJul 29, 2019
- CVE-2023-2358130Monitor
A denial-of-service vulnerability exists in the vpnserver EnSafeHttpHeaderValueStr functionality of SoftEther VPN 5.01.9674 and 5.02.
HighCVSS 7.5No exploitEPSS 1%softether · vpnOct 12, 2023
- CVE-2023-2577430Monitor
A denial-of-service vulnerability exists in the vpnserver ConnectionAccept() functionality of SoftEther VPN 5.02.
HighCVSS 7.5No exploitEPSS 1%softether · vpnOct 12, 2023
- CVE-2023-2230830Monitor
An integer underflow vulnerability exists in the vpnserver OvsProcessData functionality of SoftEther VPN 5.01.9674 and 5.02.
HighCVSS 7.5No exploitEPSS 1%softether · vpnOct 12, 2023
- CVE-2026-3931230Monitor
Pre-Auth EAP-TLS DoS on SoftEther VPN Developer Edition
HighCVSS 7.5No exploitEPSS 1%softether · softethervpnApr 7, 2026
- CVE-2023-3263429Monitor
An authentication bypass vulnerability exists in the CiRpcServerThread() functionality of SoftEther VPN 5.01.9674 and 4.41-9782-beta.
HighCVSS 7.4No exploitEPSS 0%softether · vpnOct 12, 2023
- CVE-2023-2232523Monitor
A denial of service vulnerability exists in the DCRegister DDNS_RPC_MAX_RECV_SIZE functionality of SoftEther VPN 4.41-9782-beta, 5.01.9674 a
MediumCVSS 5.9No exploitEPSS 1%softether · vpnOct 12, 2023
- CVE-2025-2556622Monitor
Memory Leak vulnerability in SoftEtherVPN 5.02.5187 allows an attacker to cause a denial of service via the UnixMemoryAlloc function.
MediumCVSS 5.6No exploitEPSS 0%softether · vpnMar 12, 2025
- CVE-2023-3119221Monitor
An information disclosure vulnerability exists in the ClientConnect() functionality of SoftEther VPN 5.01.9674.
MediumCVSS 5.3No exploitEPSS 1%softether · vpnOct 12, 2023
- CVE-2024-3852021Monitor
SoftEther VPN with L2TP - 2.75x Amplification
MediumCVSS 5.3No exploitEPSS 1%softethervpn · softethervpnJun 26, 2024
- CVE-2023-3227517Monitor
An information disclosure vulnerability exists in the CtEnumCa() functionality of SoftEther VPN 4.41-9782-beta and 5.01.9674.
MediumCVSS 4.4No exploitEPSS 0%softether · vpnOct 12, 2023