iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover credential plaintext. It requires the attacker to send a large number of messages for decryption, as described in "Everlasting ROBOT: the Marvin Attack" by Hubert Kario.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NEs Iperf3
APPEs< 3.17Netapp Bootstrap Os
OSNetappall versionsNetapp Hci Compute Node
HWNetappall versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References
Related vulnerabilities
CVE-2025-24813CRITICAL9.8⚠ KEVPL ✓same product
Apache Tomcat: Path Equivalence prowadzący do RCE i ujawnienia danych
CVE-2024-40896CRITICAL9.1PL ✓same product
XXE w bibliotece libxml2 — obejście niestandardowych handlerów SAX
CVE-2024-56337CRITICAL9.8PL ✓same product
Apache Tomcat: niekompletna mitygacja TOCTOU Race Condition (CVE-2024-50379)
CVE-2024-50379CRITICAL9.8PL ✓same product
RCE via TOCTOU Race Condition podczas kompilacji JSP w Apache Tomcat
CVE-2024-36958CRITICAL9.8PL ✓same product
Linux Kernel NFSD: błąd inicjalizacji wskaźnika w nfsd4_encode_fattr4()