Description
WireGuard, such as WireGuard 0.5.3 on Windows, does not fully account for the possibility that an adversary might be able to set a victim's system time to a future value, e.g., because unauthenticated NTP is used. This can lead to an outcome in which one static private key becomes permanently useless.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-33526 | WireGuard, such as WireGuard 0.5.3 on Windows, does not fully account for the possibility that an adversary might be able to set a victim's system time to a future value, e.g., because unauthenticated NTP is used. This can lead to an outcome in which one static private key becomes permanently useless. |
References
History
Fri, 28 Mar 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-362 | |
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-28T15:47:37.955Z
Reserved: 2023-01-29T00:00:00.000Z
Link: CVE-2021-46873
Updated: 2024-08-04T05:17:42.653Z
Status : Modified
Published: 2023-01-29T23:15:08.703
Modified: 2025-03-28T16:15:20.180
Link: CVE-2021-46873
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD