Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mv36-8276-2729

Опубликовано: 30 янв. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

WireGuard, such as WireGuard 0.5.3 on Windows, does not fully account for the possibility that an adversary might be able to set a victim's system time to a future value, e.g., because unauthenticated NTP is used. This can lead to an outcome in which one static private key becomes permanently useless.

WireGuard, such as WireGuard 0.5.3 on Windows, does not fully account for the possibility that an adversary might be able to set a victim's system time to a future value, e.g., because unauthenticated NTP is used. This can lead to an outcome in which one static private key becomes permanently useless.

EPSS

Процентиль: 19%
0.00062
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-362

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 3 лет назад

WireGuard, such as WireGuard 0.5.3 on Windows, does not fully account for the possibility that an adversary might be able to set a victim's system time to a future value, e.g., because unauthenticated NTP is used. This can lead to an outcome in which one static private key becomes permanently useless.

CVSS3: 5.3
nvd
около 3 лет назад

WireGuard, such as WireGuard 0.5.3 on Windows, does not fully account for the possibility that an adversary might be able to set a victim's system time to a future value, e.g., because unauthenticated NTP is used. This can lead to an outcome in which one static private key becomes permanently useless.

CVSS3: 5.3
debian
около 3 лет назад

WireGuard, such as WireGuard 0.5.3 on Windows, does not fully account ...

CVSS3: 8.8
fstec
больше 4 лет назад

Уязвимость реализации протокола синхронизации времени NTP VPN-сервиса WireGuard операционных систем Windows, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 19%
0.00062
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-362