CVE-2024-26306
published 2024-05-14CVE-2024-26306: iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This…
PriorityP334medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
1.10%
61.9th percentile
iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover credential plaintext. It requires the attacker to send a large number of messages for decryption, as described in "Everlasting ROBOT: the Marvin Attack" by Hubert Kario.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | iperf3 | < iperf3 3.9-1+deb11u2 (bullseye) | iperf3 3.9-1+deb11u2 (bullseye) |
| es | iperf3 | < 3.17 | 3.17 |
| es | iperf3 | >= 0 < 3.9-1+deb11u2 | 3.9-1+deb11u2 |
| es | iperf3 | >= 0 < 3.17.1-1 | 3.17.1-1 |
| es | iperf3 | >= 0 < 3.17.1-1 | 3.17.1-1 |
| es | iperf3 | >= 0 < 3.9-1+deb11u1ubuntu0.1 | 3.9-1+deb11u1ubuntu0.1 |
| es | iperf3 | >= 0 < 3.18-2ubuntu0.1 | 3.18-2ubuntu0.1 |
| es | iperf3 | >= 0 < 3.7-3ubuntu0.1~esm2 | 3.7-3ubuntu0.1~esm2 |
| es | iperf3 | >= 0 < 3.16-1ubuntu0.1~esm1 | 3.16-1ubuntu0.1~esm1 |
| msrc | azl3_iperf3_3.16-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_iperf3_3.17.1-1_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_iperf3_3.14-2_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_iperf3_3.17-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| paloalto | pan-os | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_msrc5.9MEDIUM
vendor_redhat5.9MEDIUM
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
iperf3 vulnerabilities
vendor_ubuntu·2026-01-21·CVSS 5.3
CVE-2024-26306 [MEDIUM] iperf3 vulnerabilities
Title: iperf3 vulnerabilities
Summary: Several security issues were fixed in iperf3.
Jorge Sancho Larraz discovered that iperf3 did not properly manage certain
inputs, which could cause the server process to stop responding, waiting
for input on the control connection. A remote attacker could possibly use
this issue to cause a denial of service. This issue was only addressed in
Ubuntu 22.04 LTS. (CVE-2023-7250)
It was discovered that iperf3 had a timing side-channel when performing RSA
decryption. An attacker could possibly use this issue to recover sensitive
information. This issue was only addressed in Ubuntu 20.04 LTS and Ubuntu
22.04 LTS and Ubuntu 24.04 LTS. (CVE-2024-26306)
It was discovered that iperf3 incorrectly handled certain inputs. An
attacker could possibly use this issue
Palo Alto
PAN-SA-2025-0010 Informational Bulletin: No Impact of the Marvin Attack on PAN-OS
vendor_paloalto·2025-05-14·CVSS 5.9
CVE-2024-29995 [MEDIUM] CWE-1240 PAN-SA-2025-0010 Informational Bulletin: No Impact of the Marvin Attack on PAN-OS
PAN-SA-2025-0010 Informational Bulletin: No Impact of the Marvin Attack on PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the applicability of CVEs related to the Marvin attack on PAN-OS. While we did not determine that any of these CVEs have significant impact on our PAN-OS software, some were fixed anyway out of an abundance of caution. You can also review more details about the Marvin attack if helpful. CVE Summary CVE-2024-29995 This CVE does not affect PAN-OS as PAN-OS does not have the vulnerable opensc library. CVE-2024-26306 This CVE does not affect PAN-OS as PAN-OS does not have the vulnerable iperf3 component. CVE-2024-23170 This CVE does not affect PAN-OS as PAN-OS does not have the vulnerable Mbed TLS component. CVE-2024-21484 This CVE does not aff
CISA ICS
Siemens SCALANCE W700
cisa_ics·2025-02-13
Siemens SCALANCE W700
ICS Advisory
##
Siemens SCALANCE W700
Release DateFebruary 13, 2025
Alert CodeICSA-25-044-09
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE W700
- Vulnerabilities: Double Free, Improper Restriction of Communication Channel to Intended Endpoints, Improper Resource Sh
CISA ICS
Siemens SCALANCE M-800 Family
cisa_ics·2024-11-14
Siemens SCALANCE M-800 Family
ICS Advisory
##
Siemens SCALANCE M-800 Family
Release DateNovember 14, 2024
Alert CodeICSA-24-319-06
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 8.6
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE M-800 Family
- Vulnerabilities: Out-of-bounds Read, Missing Encryption of Sensitive Data, Integer Overflow or Wraparou
Red Hat
iperf3: vulnerable to marvin attack if the authentication option is used
vendor_redhat·2024-05-15·CVSS 5.9
CVE-2024-26306 [MEDIUM] CWE-203 iperf3: vulnerable to marvin attack if the authentication option is used
iperf3: vulnerable to marvin attack if the authentication option is used
iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover credential plaintext. It requires the attacker to send a large number of messages for decryption, as described in "Everlasting ROBOT: the Marvin Attack" by Hubert Kario.
A timing-based side-channel flaw was found in iperf3. If the iperf3 server is running with the --rsa-private-key-path option, the user authentication API can be attacked.
Statement: The timing-based side-channel flaw in iperf3's handling of the --rsa-private-key-path option represents a moderate severity issue due to its potential impa
Microsoft
iPerf3 before 3.17 when used with OpenSSL before 3.2.0 as a server with RSA authentication allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attac
vendor_msrc·2024-05-14·CVSS 5.9
CVE-2024-26306 [MEDIUM] CWE-385 iPerf3 before 3.17 when used with OpenSSL before 3.2.0 as a server with RSA authentication allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attac
iPerf3 before 3.17 when used with OpenSSL before 3.2.0 as a server with RSA authentication allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover credential plaintext. It requires the attacker to send a large number of messages for decryption as described in "Everlasting ROBOT: the Marvin Attack" by Hubert Kario.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transpare
Debian
CVE-2024-26306: iperf3 - iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA aut...
vendor_debian·2024·CVSS 5.9
CVE-2024-26306 [MEDIUM] CVE-2024-26306: iperf3 - iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA aut...
iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover credential plaintext. It requires the attacker to send a large number of messages for decryption, as described in "Everlasting ROBOT: the Marvin Attack" by Hubert Kario.
Scope: local
bookworm: open
bullseye: resolved (fixed in 3.9-1+deb11u2)
forky: resolved (fixed in 3.17.1-1)
sid: resolved (fixed in 3.17.1-1)
trixie: resolved (fixed in 3.17.1-1)
OSV
iperf3 vulnerabilities
osv·2026-01-21·CVSS 5.3
CVE-2023-7250 [MEDIUM] iperf3 vulnerabilities
iperf3 vulnerabilities
Jorge Sancho Larraz discovered that iperf3 did not properly manage certain
inputs, which could cause the server process to stop responding, waiting
for input on the control connection. A remote attacker could possibly use
this issue to cause a denial of service. This issue was only addressed in
Ubuntu 22.04 LTS. (CVE-2023-7250)
It was discovered that iperf3 had a timing side-channel when performing RSA
decryption. An attacker could possibly use this issue to recover sensitive
information. This issue was only addressed in Ubuntu 20.04 LTS and Ubuntu
22.04 LTS and Ubuntu 24.04 LTS. (CVE-2024-26306)
It was discovered that iperf3 incorrectly handled certain inputs. An
attacker could possibly use this issue to cause a denial of service. This
issue was only addressed in
GHSA
GHSA-x8qh-8j65-v4j9: iPerf3 before 3
ghsa_unreviewed·2024-05-14
CVE-2024-26306 [MEDIUM] CWE-385 GHSA-x8qh-8j65-v4j9: iPerf3 before 3
iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover credential plaintext. It requires the attacker to send a large number of messages for decryption, as described in "Everlasting ROBOT: the Marvin Attack" by Hubert Kario.
OSV
CVE-2024-26306: iPerf3 before 3
osv·2024-05-14·CVSS 5.9
CVE-2024-26306 [MEDIUM] CVE-2024-26306: iPerf3 before 3
iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover credential plaintext. It requires the attacker to send a large number of messages for decryption, as described in "Everlasting ROBOT: the Marvin Attack" by Hubert Kario.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://downloads.es.net/pub/iperf/esnet-secadv-2024-0001.txt.aschttps://github.com/esnet/iperf/releases/tag/3.17https://www.insyde.com/security-pledge/SA-2024005https://downloads.es.net/pub/iperf/esnet-secadv-2024-0001.txt.aschttps://github.com/esnet/iperf/releases/tag/3.17https://lists.debian.org/debian-lts-announce/2025/01/msg00027.htmlhttps://security.netapp.com/advisory/ntap-20250228-0007/
2024-05-14
Published