CVE-2023-7250

EUVD-2023-59431
A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less than the expected amount of data to the iperf server, which can cause the server to hang indefinitely waiting for the remainder or until the connection gets closed. This will prevent other connections to the server, leading to a denial of service.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
redhatCNA
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 15%
Affected Products (NVD)
VendorProductVersion
esiperf3
𝑥
< 3.15
redhatenterprise_linux
8.0
redhatenterprise_linux
9.0
redhatenterprise_linux_for_arm_64
8.0_aarch64:_aarch64
redhatenterprise_linux_for_arm_64
9.0_aarch64:_aarch64
redhatenterprise_linux_for_ibm_z_systems
8.0_s390x:_s390x
redhatenterprise_linux_for_ibm_z_systems
9.0_s390x:_s390x
redhatenterprise_linux_for_power_little_endian
8.0_ppc64le:_ppc64le
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
iperf3
bookworm
ignored
bookworm (security)
vulnerable
bullseye
no-dsa
bullseye (security)
vulnerable
buster
no-dsa
sid
3.18-1
fixed
trixie
3.17.1-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
iperf3
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
mantic
ignored
noble
not-affected
oracular
not-affected
xenial
needs-triage