WireGuard, such as WireGuard 0.5.3 on Windows, does not fully account for the possibility that an adversary might be able to set a victims system time to a future value, e.g., because unauthenticated NTP is used. This can lead to an outcome in which one static private key becomes permanently useless.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Wireguard | Wireguard | 0.5.3 (including) | 0.5.3 (including) |
Wireguard | Ubuntu | bionic | * |
Wireguard | Ubuntu | kinetic | * |
Wireguard | Ubuntu | lunar | * |
Wireguard | Ubuntu | mantic | * |
Wireguard | Ubuntu | trusty | * |
Wireguard | Ubuntu | xenial | * |