Vulnerability record · CVE-2024-26306 · published 14 May 2024
CVE-2024-26306: Es iperf3 vulnerability
EEs · Iperf3
iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover credential plaintext. It requires the attacker to send a large number of messages for decryption, as described in "Everlasting ROBOT: the Marvin Attack" by Hubert Kario.
Description
iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover credential plaintext. It requires the attacker to send a large number of messages for decryption, as described in "Everlasting ROBOT: the Marvin Attack" by Hubert Kario.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://downloads.es.net/pub/iperf/esnet-secadv-2024-0001.txt.asc | Third Party Advisory |
| https://github.com/esnet/iperf/releases/tag/3.17 | Release Notes |
| https://www.insyde.com/security-pledge/SA-2024005 | Third Party Advisory |
| https://downloads.es.net/pub/iperf/esnet-secadv-2024-0001.txt.asc | Third Party Advisory |
| https://github.com/esnet/iperf/releases/tag/3.17 | Release Notes |
| https://lists.debian.org/debian-lts-announce/2025/01/msg00027.html | |
| https://security.netapp.com/advisory/ntap-20250228-0007/ | Third Party Advisory |
Track CVE-2024-26306 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-26306), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.