Vulnerabilities
Vulnerable Software
Es:  >> Iperf3  >> 3.16  Security Vulnerabilities
In iperf before 3.19.1, iperf_auth.c has a Base64Decode assertion failure and application exit upon a malformed authentication attempt.
CVSS Score
3.7
EPSS Score
0.001
Published
2025-08-03
In iperf before 3.19.1, iperf_auth.c has an off-by-one error and resultant heap-based buffer overflow.
CVSS Score
6.5
EPSS Score
0.001
Published
2025-08-03
iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover credential plaintext. It requires the attacker to send a large number of messages for decryption, as described in "Everlasting ROBOT: the Marvin Attack" by Hubert Kario.
CVSS Score
5.9
EPSS Score
0.006
Published
2024-05-14


Contact Us

Shodan ® - All rights reserved