← Vulnerability feed

Vulnerability record · CVE-2024-53580 · published 18 December 2024

CVE-2024-53580: Es iperf3 null pointer dereference vulnerability

EEs · Iperf3

iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function.

7.5 CVSS 3.1 High EPSS 0.92% · top 41.3% CWE-476 · NULL pointer dereference
7.5CVSS 3.1 base score
0.92%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
5References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-53580 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2024-38475Apache HTTP Server mod_rewrite improper escaping enables code executionApache HTTP Server 2.4.59 and earlier has an improper output escaping flaw in mod_rewrite. Substitutions in server context that use a backreference o…KEVEPSS 100%analysed7.8CVE-2019-13272Linux kernel ptrace credential mishandling allows local root escalationThe Linux kernel before 5.1.17 mishandles credential recording in ptrace_link (kernel/ptrace.c) when a process creates a ptrace relationship, and als…KEVEPSS 52%analysed10.0CVE-2025-54351Es iperf3 vulnerabilityIn iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).EPSS 0.41%10.0CVE-2025-54349Es iperf3 vulnerabilityIn iperf before 3.19.1, iperf_auth.c has an off-by-one error and resultant heap-based buffer overflow.EPSS 0.40%9.8CVE-2024-56171Xmlsoft libxml2 use after free vulnerabilitylibxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. …EPSS 1.2%9.8CVE-2022-37434Zlib out-of-bounds write vulnerabilityzlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only appl…EPSS 19%9.8CVE-2019-17006Siemens ruggedcom rox mx5000 firmware improper input validation vulnerabilityIn Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling th…EPSS 3.6%9.8CVE-2019-18805Linux kernel integer overflow vulnerabilityAn issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before 5.0.11. There is a net/ipv4/tcp_input.c signed integer overflow in t…EPSS 3.4%

Source: NIST National Vulnerability Database (record CVE-2024-53580), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.