V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2023-7250
ANC
Medium

A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can sen…

CVSS
5.3
Medium
EPSS
0.00
p17
Published
2023-01-01
Updated
2023-01-01
Description

A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less than the expected amount of data to the iperf server, which can cause the server to hang indefinitely waiting for the remainder or until the connection gets closed. This will prevent other connections to the server, leading to a denial of service.

Tags · CWE
Pre-auth
CWE-183
CAPEC-3
CAPEC-43
CAPEC-71
CAPEC-120
Affected products
Enterprise_linuxEnterprise_linux_for_arm_64Enterprise_linux_for_ibm_z_systemsEnterprise_linux_for_power_little_endian
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Timeline
2023-01-01
Published
2023-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: N
None (N)
Availability Impact
A: L
Low (L)
Exploit indicators
EPSS
0.001 · p17
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected software
ProductVendorStatus
Tracked
iperf3Tracked
iperf3Tracked
iperf3Tracked
iperf3Tracked
iperf3Tracked
iperf3Tracked
iperf3Tracked
iperf3Tracked
iperf3Tracked
iperf3Tracked
iperf3Tracked
iperf3Tracked
iperf3Tracked
libiperf3-0Tracked
libiperf3-develTracked
enterprise_linux*Tracked
enterprise_linux_for_arm_64*Tracked
enterprise_linux_for_ibm_z_systems*Tracked
enterprise_linux_for_power_little_endian*Tracked
Source databases
ANC
DEB
CVE
RED
UBU
Related vulnerabilities