Introducing Wiz for Exposure Management: Unify, prioritize, and remediate exposures everywhere.

CVE-2025-54350
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-54350 is a security vulnerability discovered in iperf versions before 3.19.1, specifically affecting the authentication mechanism. The vulnerability was identified in the iperf_auth.c file, where a Base64Decode assertion failure occurs upon malformed authentication attempts. The issue was reported by Han Lee from Apple Information Security and was disclosed on July 25, 2025 (GitHub Release).

Technical details

The vulnerability stems from an assertion check in the Base64Decode function within iperf_auth.c that would trigger a failure and cause the application to exit when encountering malformed authentication attempts. The vulnerability has been assigned a CVSS v3.1 score of 3.7 (LOW) with the vector string CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L. The weakness has been classified as CWE-617 (Reachable Assertion) (NVD).

Impact

When exploited, this vulnerability causes the iperf application to exit unexpectedly upon receiving malformed authentication attempts. This can result in a denial of service condition, affecting the availability of the iperf service (NVD).

Mitigation and workarounds

The vulnerability has been fixed in iperf version 3.19.1 by removing the problematic assertion check. Users are strongly recommended to upgrade to version 3.19.1 or later to address this security issue (GitHub Release).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management