ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (interleaved-mode transition and time change) via a spoofed broadcast packet. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-1548.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux | — | Upgrade ntp | Aug 1, 2016 | Jul 4, 2016 |
| Cisco Apic | — | Upgrade to the latest version of Cisco APIC to resolve this vulnerability. | May 11, 2026 | Jun 3, 2016 |
| Cisco Xe | — | Upgrade to the latest version of Cisco IOS XE | Jul 30, 2019 | Jul 5, 2016 |
| Debian | — | Upgrade ntp | Jul 30, 2024 | Jul 5, 2016 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Jun 16, 2016 |
| Freebsd | — | Upgrade FreeBSD | Dec 10, 2025 | Aug 11, 2016 |
| Gentoo Linux | — | Upgrade net-misc/ntp. | Oct 30, 2017 | Jul 4, 2016 |
| Huawei Euleros 2_0_sp1 | — | Upgrade ntpUpgrade ntpdate | Nov 30, 2017 | Jul 4, 2016 |
| Huawei Euleros 2_0_sp2 | — | Upgrade ntpUpgrade ntpdate | Nov 30, 2017 | Jul 4, 2016 |
| Ntp | — | Upgrade NTP to version 4.2.8Upgrade NTP to version 4.3.93 | Feb 23, 2023 | Jul 5, 2016 |
| Oracle Solaris | — | Upgrade service/network/ntp to version 4.2.8.8-0.175.3.12.0.1.0 on Solaris 11.3 | May 29, 2017 | Jul 4, 2016 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 2, 2016 |
| Suse | — | Upgrade ntpUpgrade ntp-doc | Jun 13, 2016 | Jun 13, 2016 |
| Ubuntu | — | Upgrade ntp | Oct 7, 2016 | Jul 4, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub