← Vulnerability feed

Vulnerability record · CVE-2024-26306 · published 14 May 2024

CVE-2024-26306: Es iperf3 vulnerability

EEs · Iperf3

iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover credential plaintext. It requires the attacker to send a large number of messages for decryption, as described in "Everlasting ROBOT: the Marvin Attack" by Hubert Kario.

5.9 CVSS 3.1 Medium EPSS 1.1% · top 35.7% CWE-385 · CWE-385
5.9CVSS 3.1 base score
1.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
7References
17 Jun 2026Last modified by NVD

Description

iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover credential plaintext. It requires the attacker to send a large number of messages for decryption, as described in "Everlasting ROBOT: the Marvin Attack" by Hubert Kario.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-26306 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-24813Apache Tomcat Default Servlet path equivalence enables RCE and file disclosureApache Tomcat mishandles path equivalence for names containing an internal dot, letting a remote unauthenticated attacker write files through the Def…KEVEPSS 100%analysed7.8CVE-2024-1086Linux kernel nf_tables use-after-free allows local privilege escalationThe Linux kernel's netfilter nf_tables component has a use-after-free in nft_verdict_init(), where positive drop errors are accepted and nf_hook_slow…KEVEPSS 28%analysed7.8CVE-2023-4911GNU C Library ld.so GLIBC_TUNABLES heap buffer overflowThe GNU C Library dynamic loader ld.so mishandles the GLIBC_TUNABLES environment variable, causing a heap-based buffer overflow and out-of-bounds wri…KEVEPSS 81%analysed7.8CVE-2022-0492Linux kernel cgroups v1 release_agent privilege escalation and container escapeThe Linux kernel's cgroup_release_agent_write in kernel/cgroup/cgroup-v1.c mishandles authorization, letting the cgroups v1 release_agent feature be …KEVEPSS 5.5%analysed10.0CVE-2025-54351Es iperf3 vulnerabilityIn iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).EPSS 0.41%10.0CVE-2025-54349Es iperf3 vulnerabilityIn iperf before 3.19.1, iperf_auth.c has an off-by-one error and resultant heap-based buffer overflow.EPSS 0.40%9.8CVE-2024-56337Apache tomcat toctou race condition vulnerabilityTime-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, fr…EPSS 9.0%9.8CVE-2024-50379Apache tomcat toctou race condition vulnerabilityTime-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file syste…EPSS 32%

Source: NIST National Vulnerability Database (record CVE-2024-26306), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.