Es Iperf3 vulnerabilities
8 known vulnerabilities affecting es/iperf3.
Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH2MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2025-54349CRITICALCVSS 10.0≥ 3.2, < 3.19.1fixed in 3.19.12025-08-03
CVE-2025-54349 [MEDIUM] CWE-193 CVE-2025-54349: In iperf before 3.19.1, iperf_auth.c has an off-by-one error and resultant heap-based buffer overflo
In iperf before 3.19.1, iperf_auth.c has an off-by-one error and resultant heap-based buffer overflow.
cvelistv5nvd
CVE-2025-54351CRITICALCVSS 10.0v3.19fixed in 3.19.12025-08-03
CVE-2025-54351 [HIGH] CWE-420 CVE-2025-54351: In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in re
In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).
cvelistv5nvd
CVE-2025-54350MEDIUMCVSS 5.3≥ 3.2, < 3.19.1fixed in 3.19.12025-08-03
CVE-2025-54350 [LOW] CWE-617 CVE-2025-54350: In iperf before 3.19.1, iperf_auth.c has a Base64Decode assertion failure and application exit upon
In iperf before 3.19.1, iperf_auth.c has a Base64Decode assertion failure and application exit upon a malformed authentication attempt.
cvelistv5nvd
CVE-2024-53580HIGHCVSS 7.5v3.17.12024-12-18
CVE-2024-53580 [HIGH] CWE-476 CVE-2024-53580: iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters()
iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function.
nvd
CVE-2024-26306MEDIUMCVSS 5.9fixed in 3.172024-05-14
CVE-2024-26306 [MEDIUM] CWE-385 CVE-2024-26306: iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows
iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover credential plaintext. It requires the attacker to send a large number of messages for decryption, as described in "Everlasting ROBOT: t
nvd
CVE-2023-7250MEDIUMCVSS 5.3fixed in 3.152024-03-18
CVE-2023-7250 [MEDIUM] CWE-183 CVE-2023-7250: A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A mal
A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less than the expected amount of data to the iperf server, which can cause the server to hang indefinitely waiting for the remainder or until the connection gets closed. This will prevent other connections to the
nvd
CVE-2023-38403HIGHCVSS 7.5fixed in 3.142023-07-17
CVE-2023-38403 [HIGH] CWE-190 CVE-2023-38403: iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted lengt
iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field.
nvd
CVE-2016-4303CRITICALCVSS 9.8≥ 3.0, < 3.0.12≥ 3.1, < 3.1.32016-09-26
CVE-2016-4303 [CRITICAL] CWE-120 CVE-2016-4303: The parse_string function in cjson.c in the cJSON library mishandles UTF8/16 strings, which allows r
The parse_string function in cjson.c in the cJSON library mishandles UTF8/16 strings, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a non-hex character in a JSON string, which triggers a heap-based buffer overflow.
nvd