VendorsEsiperf3all versions
Vulnerabilities

Es Energy Sciences Network (ESnet) iperf3

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2025-54351
In iperf before 3.19.1, net.c has a buffer overflow when --skip-rx-copy is used (for MSG_TRUNC in recv).
Published 2025-08-03 · Analyzed
10.0EPSS 0.004
CVE-2025-54349
In iperf before 3.19.1, iperf_auth.c has an off-by-one error and resultant heap-based buffer overflow.
Published 2025-08-03 · Modified
10.0EPSS 0.004
CVE-2016-4303
The parse_string function in cjson.c in the cJSON library mishandles UTF8/16 strings, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a non-hex character in a JSON string, which triggers a heap-based buffer overflow.
Published 2016-09-26 · Modified
9.8EPSS 0.070
CVE-2023-38403
iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field.
Published 2023-07-17 · Modified
7.5EPSS 0.020
CVE-2024-53580
iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function.
Published 2024-12-18 · Modified
7.5EPSS 0.009
CVE-2024-26306
iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover credential plaintext. It requires the attacker to send a large number of messages for decryption, as described in "Everlasting ROBOT: the Marvin Attack" by Hubert Kario.
Published 2024-05-13 · Modified
5.9EPSS 0.011
CVE-2023-7250
Iperf3: possible denial of service
Published 2024-03-18 · Modified
5.3EPSS 0.009
CVE-2025-54350
In iperf before 3.19.1, iperf_auth.c has a Base64Decode assertion failure and application exit upon a malformed authentication attempt.
Published 2025-08-03 · Modified
5.3EPSS 0.004