Timing Side Channel Vulnerability in iPerf3 with OpenSSL under RSA Authentication
CVE-2024-26306
5.9MEDIUM
What is CVE-2024-26306?
iPerf3, when deployed with OpenSSL versions older than 3.2.0 and utilizing RSA authentication, presents a vulnerability due to a timing side channel in its decryption operations. This flaw enables attackers to glean sensitive credential information through meticulous analysis of the timing of responses. The attack exploits the need for an attacker to send a large volume of messages to facilitate the decryption process. For comprehensive security, users should ensure they are running the latest version of iPerf3 and OpenSSL to mitigate potential risks associated with this vulnerability.
