iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover credential plaintext. It requires the attacker to send a large number of messages for decryption, as described in "Everlasting ROBOT: the Marvin Attack" by Hubert Kario.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade iperf3 | Jul 4, 2024 | May 14, 2024 |
| Debian | — | Upgrade iperf3 | Jan 30, 2025 | May 14, 2024 |
| Oracle_linux | — | Upgrade iperf3 | Jul 3, 2024 | May 15, 2024 |
| Redhat_linux | — | Upgrade iperf3-debuginfoNo solution existsUpgrade iperf3Upgrade iperf3-debugsource | Jul 3, 2024 | May 14, 2024 |
| Rocky_linux | — | Upgrade iperf3Upgrade iperf3-debugsourceUpgrade iperf3-debuginfo | Mar 18, 2025 | May 14, 2024 |
| Suse | — | Upgrade iperf-develUpgrade iperfUpgrade libiperf0 | Jun 12, 2024 | May 14, 2024 |
| Ubuntu | — | Upgrade libiperf0Upgrade libiperf0 (Ubuntu Pro)Upgrade iperf3 (Ubuntu Pro)Upgrade iperf3 | Jan 22, 2026 | Jan 21, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jul 2, 2025 | May 13, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub