softether CVE Vulnerabilities & Metrics

Focus on softether vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About softether Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with softether. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total softether CVEs: 10
Earliest CVE date: 29 Jul 2019, 17:15 UTC
Latest CVE date: 12 Oct 2023, 16:15 UTC

Latest CVE reference: CVE-2023-32634

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical softether CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 0.46

Max CVSS: 4.6

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 9
4.0-6.9 1
7.0-8.9 0
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS softether CVEs

These are the five CVEs with the highest CVSS scores for softether, sorted by severity first and recency.

All CVEs for softether

CVE-2023-32634 softether vulnerability CVSS: 0 12 Oct 2023, 16:15 UTC

An authentication bypass vulnerability exists in the CiRpcServerThread() functionality of SoftEther VPN 5.01.9674 and 4.41-9782-beta. An attacker can perform a local man-in-the-middle attack to trigger this vulnerability.

CVE-2023-32275 softether vulnerability CVSS: 0 12 Oct 2023, 16:15 UTC

An information disclosure vulnerability exists in the CtEnumCa() functionality of SoftEther VPN 4.41-9782-beta and 5.01.9674. Specially crafted network packets can lead to a disclosure of sensitive information. An attacker can send packets to trigger this vulnerability.

CVE-2023-31192 softether vulnerability CVSS: 0 12 Oct 2023, 16:15 UTC

An information disclosure vulnerability exists in the ClientConnect() functionality of SoftEther VPN 5.01.9674. A specially crafted network packet can lead to a disclosure of sensitive information. An attacker can perform a man-in-the-middle attack to trigger this vulnerability.

CVE-2023-27516 softether vulnerability CVSS: 0 12 Oct 2023, 16:15 UTC

An authentication bypass vulnerability exists in the CiRpcAccepted() functionality of SoftEther VPN 4.41-9782-beta and 5.01.9674. A specially crafted network packet can lead to unauthorized access. An attacker can send a network request to trigger this vulnerability.

CVE-2023-27395 softether vulnerability CVSS: 0 12 Oct 2023, 16:15 UTC

A heap-based buffer overflow vulnerability exists in the vpnserver WpcParsePacket() functionality of SoftEther VPN 4.41-9782-beta, 5.01.9674 and 5.02. A specially crafted network packet can lead to arbitrary code execution. An attacker can perform a man-in-the-middle attack to trigger this vulnerability.

CVE-2023-25774 softether vulnerability CVSS: 0 12 Oct 2023, 16:15 UTC

A denial-of-service vulnerability exists in the vpnserver ConnectionAccept() functionality of SoftEther VPN 5.02. A set of specially crafted network connections can lead to denial of service. An attacker can send a sequence of malicious packets to trigger this vulnerability.

CVE-2023-23581 softether vulnerability CVSS: 0 12 Oct 2023, 16:15 UTC

A denial-of-service vulnerability exists in the vpnserver EnSafeHttpHeaderValueStr functionality of SoftEther VPN 5.01.9674 and 5.02. A specially crafted network packet can lead to denial of service.

CVE-2023-22325 softether vulnerability CVSS: 0 12 Oct 2023, 16:15 UTC

A denial of service vulnerability exists in the DCRegister DDNS_RPC_MAX_RECV_SIZE functionality of SoftEther VPN 4.41-9782-beta, 5.01.9674 and 5.02. A specially crafted network packet can lead to denial of service. An attacker can perform a man-in-the-middle attack to trigger this vulnerability.

CVE-2023-22308 softether vulnerability CVSS: 0 12 Oct 2023, 16:15 UTC

An integer underflow vulnerability exists in the vpnserver OvsProcessData functionality of SoftEther VPN 5.01.9674 and 5.02. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.

CVE-2019-11868 softether vulnerability CVSS: 4.6 29 Jul 2019, 17:15 UTC

See.sys, up to version 4.25, in SoftEther VPN Server versions 4.29 or older, allows a user to call an IOCTL specifying any kernel address to which arbitrary bytes are written to.