CVE-2023-27516
About
An authentication bypass vulnerability exists in the CiRpcAccepted() functionality of SoftEther VPN 4.41-9782-beta and 5.01.9674. A specially crafted network packet can lead to unauthorized access. An attacker can send a network request to trigger this vulnerability.
Rainforest analyst review
An authentication bypass exists in SoftEther VPN's CiRpcAccepted() handling in the 4.41-9782-beta and 5.01.9674 releases: a specially crafted network packet can gain unauthorized access. Notably the vector is local rather than fully remote, and the affected builds are beta/development releases, so the realistic exposure is narrower than an 'auth bypass on a VPN' headline first suggests.
Auth bypass on VPN software is inherently attractive because VPNs are the trusted gateway into internal networks, but two things temper this one: the local attack vector limits who can reach the vulnerable RPC path, and the specific affected versions are betas that responsible deployments are unlikely to be running in production. That combination keeps it well out of mass-scanning territory.
We would rank this below its 7.3 for most environments and gate the whole assessment on a simple question, are we running one of these exact beta builds anywhere. If not, it is informational. If we are, the action is straightforward: move off the beta to a fixed stable release, and in the meantime constrain who can reach the affected local RPC surface.
References
Related CVEs
No related CVEs.
Frequently asked questions
What is CVE-2023-27516?
An authentication bypass vulnerability exists in the CiRpcAccepted() functionality of SoftEther VPN 4.41-9782-beta and 5.01.9674. A specially crafted network packet can lead to unauthorized access. An attacker can send a network request to trigger this vulnerability.
How severe is CVE-2023-27516?
CVE-2023-27516 carries a CVSS 3.1 base score of 7.3, rated high. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 69 out of 100, in the elevated band.
How is CVE-2023-27516 exploited?
According to the CVSS vector (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L): attack vector Local, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity Low and availability Low.
Which products are affected by CVE-2023-27516?
Public advisories list the following as affected: vpn. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2023-27516?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
