CVE-2024-38520 - CVE House
Back to Database
Status published Medium CVE-2024-38520

SoftEther VPN with L2TP - 2.75x Amplification

Vulnerability Description

SoftEtherVPN is a an open-source cross-platform multi-protocol VPN Program. When SoftEtherVPN is deployed with L2TP enabled on a device, it introduces the possibility of the host being used for amplification/reflection traffic generation because it will respond to every packet with two response packets that are larger than the request packet size. These sorts of techniques are used by external actors who generate spoofed source IPs to target a destination on the internet. This vulnerability has been patched in version 5.02.5185.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-38520

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

SoftEtherVPN

View all reports →

Affected Software

SoftEtherVPN
Vulnerable Versions:
<= 5.02.5183

Timeline

Official Publish: June 26th, 2024
Last Modified: August 2nd, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Weaknesses (CWE)