Segmentation Violation in iperf Affects Network Performance
CVE-2024-53580

7.5HIGH

Key Information:

Vendor

ESnet

Vendor
CVE Published:
18 December 2024

What is CVE-2024-53580?

CVE-2024-53580 is a critical segmentation violation vulnerability found in iperf version 3.17.1, specifically within the iperf_exchange_parameters() function. This vulnerability can lead to unexpected behavior, crashes, or denial of service, significantly impacting the performance and reliability of network applications utilizing the iperf tool. Users of iperf are advised to upgrade to the latest version to mitigate potential risks associated with this vulnerability.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.