CVE-2021-46873 affects WireGuard, specifically version 0.5.3 on Windows, due to its insufficient handling of manipulated system times. An attacker could exploit this by setting a victim's system time to a future date, potentially rendering a static private key permanently unusable. This vulnerability has a CVSS score of 5.3 (Medium), indicating a low impact on availability and requiring no user interaction or privileges for exploitation. There is currently no evidence of active exploitation, nor are there publicly available exploit codes like Metasploit or ExploitDB modules. Community discussion is minimal, with only one mention found.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.5.3CPE matchmatch criteria | cpe:2.3:a:wireguard:wireguard:0.5.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.