Vulnerability Description
Sing-box is an open source proxy system. Affected versions are subject to an authentication bypass when specially crafted requests are sent to sing-box. This affects all SOCKS5 inbounds with user authentication and an attacker may be able to bypass authentication. Users are advised to update to sing-box 1.4.4 or to 1.5.0-rc.4. Users unable to update should not expose the SOCKS5 inbound to insecure environments.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sagernet | Sing-Box | < 1.4.5 |
Related Weaknesses (CWE)
References
- https://github.com/SagerNet/sing-box/security/advisories/GHSA-r5hm-mp3j-285gVendor Advisory
- https://github.com/SagerNet/sing-box/security/advisories/GHSA-r5hm-mp3j-285gVendor Advisory
FAQ
What is CVE-2023-43644?
CVE-2023-43644 is a vulnerability with a CVSS score of 9.1 (CRITICAL). Sing-box is an open source proxy system. Affected versions are subject to an authentication bypass when specially crafted requests are sent to sing-box. This affects all SOCKS5 inbounds with user auth...
How severe is CVE-2023-43644?
CVE-2023-43644 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-43644?
Check the references section above for vendor advisories and patch information. Affected products include: Sagernet Sing-Box.