CVE-2023-43644

Sing-box is an open source proxy system. Affected versions are subject to an authentication bypass when specially crafted requests are sent to sing-box. This affects all SOCKS5 inbounds with user authentication and an attacker may be able to bypass authentication. Users are advised to update to sing-box 1.4.4 or to 1.5.0-rc.4. Users unable to update should not expose the SOCKS5 inbound to insecure environments.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.1 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
GitHub_MCNA
9.1 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 39%
VendorProductVersion
sagernetsing-box
𝑥
< 1.4.5
sagernetsing-box
1.5.0:beta1
sagernetsing-box
1.5.0:beta10
sagernetsing-box
1.5.0:beta11
sagernetsing-box
1.5.0:beta12
sagernetsing-box
1.5.0:beta2
sagernetsing-box
1.5.0:beta3
sagernetsing-box
1.5.0:beta4
sagernetsing-box
1.5.0:beta5
sagernetsing-box
1.5.0:beta6
sagernetsing-box
1.5.0:beta7
sagernetsing-box
1.5.0:beta8
sagernetsing-box
1.5.0:beta9
sagernetsing-box
1.5.0:rc1
sagernetsing-box
1.5.0:rc2
sagernetsing-box
1.5.0:rc3
𝑥
= Vulnerable software versions