2024-08-20 06:03:13 +00:00

33 lines
1.5 KiB
JSON

{
"id": "CVE-2024-26306",
"sourceIdentifier": "cve@mitre.org",
"published": "2024-05-14T15:08:51.197",
"lastModified": "2024-08-20T05:15:12.073",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover credential plaintext. It requires the attacker to send a large number of messages for decryption, as described in \"Everlasting ROBOT: the Marvin Attack\" by Hubert Kario."
},
{
"lang": "es",
"value": "iPerf3 anterior a 3.17, cuando se usa con OpenSSL anterior a 3.2.0 como servidor con autenticaci\u00f3n RSA, permite un canal lateral de temporizaci\u00f3n en las operaciones de descifrado RSA. Este canal lateral podr\u00eda ser suficiente para que un atacante recupere el texto sin formato de las credenciales. Requiere que el atacante env\u00ede una gran cantidad de mensajes para descifrarlos, como se describe en \"Everlasting ROBOT: the Marvin Attack\" de Hubert Kario."
}
],
"metrics": {},
"references": [
{
"url": "https://downloads.es.net/pub/iperf/esnet-secadv-2024-0001.txt.asc",
"source": "cve@mitre.org"
},
{
"url": "https://github.com/esnet/iperf/releases/tag/3.17",
"source": "cve@mitre.org"
},
{
"url": "https://www.insyde.com/security-pledge/SA-2024005",
"source": "cve@mitre.org"
}
]
}