Base64Decode Assertion Failure in iperf Affected by Malformed Authentication Attempt
CVE-2025-54350

5.3MEDIUM

Key Information:

Vendor

Es

Status
Vendor
CVE Published:
3 August 2025

What is CVE-2025-54350?

The iperf software prior to version 3.19.1 contains a vulnerability in the iperf_auth.c module that leads to an assertion failure during Base64 decoding. This issue can be triggered by a malformed authentication attempt, resulting in an unexpected application exit. Users of this version are advised to upgrade to mitigate potential disruptions and enhance the security of their authentication processes.

Affected Version(s)

iperf3 0 < 3.19.1

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.