Vulnerability Description
In iperf before 3.19.1, iperf_auth.c has a Base64Decode assertion failure and application exit upon a malformed authentication attempt.
CVSS Score
3.7
LOW
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Es | Iperf3 | >= 3.2, < 3.19.1 |
Related Weaknesses (CWE)
References
- https://github.com/esnet/iperf/commit/4eab661da0bbaac04493fa40164e928c6df7934aPatch
- https://github.com/esnet/iperf/releases/tag/3.19.1Release Notes
- https://lists.debian.org/debian-lts-announce/2025/08/msg00020.html
FAQ
What is CVE-2025-54350?
CVE-2025-54350 is a vulnerability with a CVSS score of 3.7 (LOW). In iperf before 3.19.1, iperf_auth.c has a Base64Decode assertion failure and application exit upon a malformed authentication attempt.
How severe is CVE-2025-54350?
CVE-2025-54350 has been rated LOW with a CVSS base score of 3.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-54350?
Check the references section above for vendor advisories and patch information. Affected products include: Es Iperf3.