CVE-2023-7250
published 2024-03-18CVE-2023-7250: A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less than the…
PriorityP428medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
0.93%
56.7th percentile
A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less than the expected amount of data to the iperf server, which can cause the server to hang indefinitely waiting for the remainder or until the connection gets closed. This will prevent other connections to the server, leading to a denial of service.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | iperf3 | < iperf3 3.9-1+deb11u2 (bullseye) | iperf3 3.9-1+deb11u2 (bullseye) |
| es | iperf3 | < 3.15 | 3.15 |
| es | iperf3 | >= 0 < 3.9-1+deb11u2 | 3.9-1+deb11u2 |
| es | iperf3 | >= 0 < 3.15-1 | 3.15-1 |
| es | iperf3 | >= 0 < 3.15-1 | 3.15-1 |
| es | iperf3 | >= 0 < 3.9-1+deb11u1ubuntu0.1 | 3.9-1+deb11u1ubuntu0.1 |
| es | iperf3 | >= 0 < 3.18-2ubuntu0.1 | 3.18-2ubuntu0.1 |
| es | iperf3 | >= 0 < 3.7-3ubuntu0.1~esm2 | 3.7-3ubuntu0.1~esm2 |
| es | iperf3 | >= 0 < 3.16-1ubuntu0.1~esm1 | 3.16-1ubuntu0.1~esm1 |
| msrc | cbl2_iperf3_3.14-2_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_iperf3_3.17-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_for_arm_64 | — | — |
| redhat | enterprise_linux_for_arm_64 | — | — |
| redhat | enterprise_linux_for_ibm_z_systems | — | — |
| redhat | enterprise_linux_for_ibm_z_systems | — | — |
| redhat | enterprise_linux_for_power_little_endian | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_msrc5.3MEDIUM
vendor_redhat5.3MEDIUM
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
iperf3 vulnerabilities
vendor_ubuntu·2026-01-21·CVSS 5.3
CVE-2024-26306 [MEDIUM] iperf3 vulnerabilities
Title: iperf3 vulnerabilities
Summary: Several security issues were fixed in iperf3.
Jorge Sancho Larraz discovered that iperf3 did not properly manage certain
inputs, which could cause the server process to stop responding, waiting
for input on the control connection. A remote attacker could possibly use
this issue to cause a denial of service. This issue was only addressed in
Ubuntu 22.04 LTS. (CVE-2023-7250)
It was discovered that iperf3 had a timing side-channel when performing RSA
decryption. An attacker could possibly use this issue to recover sensitive
information. This issue was only addressed in Ubuntu 20.04 LTS and Ubuntu
22.04 LTS and Ubuntu 24.04 LTS. (CVE-2024-26306)
It was discovered that iperf3 incorrectly handled certain inputs. An
attacker could possibly use this issue
CISA ICS
Siemens SCALANCE W700
cisa_ics·2025-02-13
Siemens SCALANCE W700
ICS Advisory
##
Siemens SCALANCE W700
Release DateFebruary 13, 2025
Alert CodeICSA-25-044-09
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE W700
- Vulnerabilities: Double Free, Improper Restriction of Communication Channel to Intended Endpoints, Improper Resource Sh
Microsoft
Iperf3: possible denial of service
vendor_msrc·2024-03-12·CVSS 5.3
CVE-2023-7250 [MEDIUM] CWE-183 Iperf3: possible denial of service
Iperf3: possible denial of service
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-u
Red Hat
iperf3: possible denial of service
vendor_redhat·2023-10-16·CVSS 5.3
CVE-2023-7250 [MEDIUM] CWE-183 iperf3: possible denial of service
iperf3: possible denial of service
A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less than the expected amount of data to the iperf server, which can cause the server to hang indefinitely waiting for the remainder or until the connection gets closed. This will prevent other connections to the server, leading to a denial of service.
A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less than the expected amount of data to the iperf server, which can cause the server to hang indefinitely waiting for the remainder or until the connection gets closed. This will prevent other connections to the server, leading
Debian
CVE-2023-7250: iperf3 - A flaw was found in iperf, a utility for testing network performance using TCP, ...
vendor_debian·2023·CVSS 5.3
CVE-2023-7250 [MEDIUM] CVE-2023-7250: iperf3 - A flaw was found in iperf, a utility for testing network performance using TCP, ...
A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less than the expected amount of data to the iperf server, which can cause the server to hang indefinitely waiting for the remainder or until the connection gets closed. This will prevent other connections to the server, leading to a denial of service.
Scope: local
bookworm: open
bullseye: resolved (fixed in 3.9-1+deb11u2)
forky: resolved (fixed in 3.15-1)
sid: resolved (fixed in 3.15-1)
trixie: resolved (fixed in 3.15-1)
OSV
iperf3 vulnerabilities
osv·2026-01-21·CVSS 5.3
CVE-2023-7250 [MEDIUM] iperf3 vulnerabilities
iperf3 vulnerabilities
Jorge Sancho Larraz discovered that iperf3 did not properly manage certain
inputs, which could cause the server process to stop responding, waiting
for input on the control connection. A remote attacker could possibly use
this issue to cause a denial of service. This issue was only addressed in
Ubuntu 22.04 LTS. (CVE-2023-7250)
It was discovered that iperf3 had a timing side-channel when performing RSA
decryption. An attacker could possibly use this issue to recover sensitive
information. This issue was only addressed in Ubuntu 20.04 LTS and Ubuntu
22.04 LTS and Ubuntu 24.04 LTS. (CVE-2024-26306)
It was discovered that iperf3 incorrectly handled certain inputs. An
attacker could possibly use this issue to cause a denial of service. This
issue was only addressed in
OSV
CVE-2023-7250: A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP
osv·2024-03-18·CVSS 5.3
CVE-2023-7250 [MEDIUM] CVE-2023-7250: A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP
A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less than the expected amount of data to the iperf server, which can cause the server to hang indefinitely waiting for the remainder or until the connection gets closed. This will prevent other connections to the server, leading to a denial of service.
GHSA
GHSA-g636-8hgg-7gx9: A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP
ghsa_unreviewed·2024-03-18
CVE-2023-7250 [MEDIUM] CWE-183 GHSA-g636-8hgg-7gx9: A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP
A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less than the expected amount of data to the iperf server, which can cause the server to hang indefinitely waiting for the remainder or until the connection gets closed. This will prevent other connections to the server, leading to a denial of service.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2024:4241https://access.redhat.com/errata/RHSA-2024:9185https://access.redhat.com/security/cve/CVE-2023-7250https://bugzilla.redhat.com/show_bug.cgi?id=2244707https://access.redhat.com/errata/RHSA-2024:4241https://access.redhat.com/security/cve/CVE-2023-7250https://bugzilla.redhat.com/show_bug.cgi?id=2244707https://lists.debian.org/debian-lts-announce/2025/01/msg00027.html
2024-03-18
Published