Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-46873

Опубликовано: 29 янв. 2023
Источник: debian
EPSS Низкий

Описание

WireGuard, such as WireGuard 0.5.3 on Windows, does not fully account for the possibility that an adversary might be able to set a victim's system time to a future value, e.g., because unauthenticated NTP is used. This can lead to an outcome in which one static private key becomes permanently useless.

Примечания

  • Generic protocol issue in WireGuard

EPSS

Процентиль: 19%
0.00062
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 3 лет назад

WireGuard, such as WireGuard 0.5.3 on Windows, does not fully account for the possibility that an adversary might be able to set a victim's system time to a future value, e.g., because unauthenticated NTP is used. This can lead to an outcome in which one static private key becomes permanently useless.

CVSS3: 5.3
nvd
около 3 лет назад

WireGuard, such as WireGuard 0.5.3 on Windows, does not fully account for the possibility that an adversary might be able to set a victim's system time to a future value, e.g., because unauthenticated NTP is used. This can lead to an outcome in which one static private key becomes permanently useless.

CVSS3: 5.3
github
около 3 лет назад

WireGuard, such as WireGuard 0.5.3 on Windows, does not fully account for the possibility that an adversary might be able to set a victim's system time to a future value, e.g., because unauthenticated NTP is used. This can lead to an outcome in which one static private key becomes permanently useless.

CVSS3: 8.8
fstec
больше 4 лет назад

Уязвимость реализации протокола синхронизации времени NTP VPN-сервиса WireGuard операционных систем Windows, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 19%
0.00062
Низкий