Beveiligingsadvies

CVE-2025-32787

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-04-16 21:41:15
Laatst bijgewerkt 2025-04-17 13:15:18
Toegewezen door GitHub_M
CVSS-score 3.1
Status PUBLISHED

Beschrijving

SoftEtherVPN is a an open-source cross-platform multi-protocol VPN Program. Versions 5.02.5184 to 5.02.5187 are vulnerable to NULL dereference in `DeleteIPv6DefaultRouterInRA` called by `StorePacket`. Before dereferencing, `DeleteIPv6DefaultRouterInRA` does not account for `ParsePacket` returning NULL, resulting in the program crashing. A patched version does not exist at this time.