An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticated network packet can be used to reset the expected origin timestamp for target peers. Legitimate replies from targeted peers will fail the origin timestamp check (TEST2) causing the reply to be dropped and creating a denial of service condition.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
- CVSS 3.0 Base Score: 3.7
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Ntp | — | Upgrade macOS to the latest version | Sep 26, 2017 | Sep 26, 2017 |
| Debian | — | Upgrade ntp | Jul 30, 2024 | Jun 4, 2018 |
| Freebsd | — | Upgrade FreeBSD | May 26, 2017 | May 26, 2017 |
| Hpux | — | Update NTP to the latest version | Dec 9, 2019 | Jun 4, 2018 |
| Ntp | — | Upgrade to the latest version of NTP | Feb 23, 2023 | Jun 4, 2018 |
| Oracle Solaris | — | Upgrade service/network/ntp to version 4.2.8.10-0.175.3.20.0.2.0 on Solaris 11.3 | Jun 8, 2017 | Jun 8, 2017 |
| Panos | — | Update PAN-OS 8.0 to the latest workaround for your device | Jul 27, 2017 | Apr 18, 2017 |
| Suse | — | Upgrade ntpUpgrade ntp-doc | Apr 19, 2017 | Apr 18, 2017 |
| Ubuntu | — | Upgrade ntp | Jul 6, 2017 | Apr 18, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub