CVE Vulnerabilities

CVE-2021-46873

Published: Jan 29, 2023 | Modified: Mar 28, 2025
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

WireGuard, such as WireGuard 0.5.3 on Windows, does not fully account for the possibility that an adversary might be able to set a victims system time to a future value, e.g., because unauthenticated NTP is used. This can lead to an outcome in which one static private key becomes permanently useless.

Affected Software

NameVendorStart VersionEnd Version
WireguardWireguard0.5.3 (including)0.5.3 (including)
WireguardUbuntubionic*
WireguardUbuntufocal*
WireguardUbuntukinetic*
WireguardUbuntulunar*
WireguardUbuntumantic*
WireguardUbuntuoracular*
WireguardUbuntuplucky*
WireguardUbuntutrusty*
WireguardUbuntuxenial*

References