CVE-2021-46873

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
29/01/2023
Last modified:
28/03/2025

Description

WireGuard, such as WireGuard 0.5.3 on Windows, does not fully account for the possibility that an adversary might be able to set a victim's system time to a future value, e.g., because unauthenticated NTP is used. This can lead to an outcome in which one static private key becomes permanently useless.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wireguard:wireguard:0.5.3:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*