ntpd in ntp 4.2.x before 4.2.8p7 and 4.3.x before 4.3.92 allows authenticated users that know the private symmetric key to create arbitrarily-many ephemeral associations in order to win the clock selection of ntpd and modify a victim's clock via a Sybil attack. This issue exists because of an incomplete fix for CVE-2016-1549.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux | — | amazon-linux-upgrade-ntp | May 11, 2018 | Mar 6, 2018 |
| Arch Linux | arch-linux-upgrade-latest | Jul 11, 2025 | Mar 6, 2018 | |
| Debian | debian-upgrade-ntp | Jul 30, 2024 | Mar 6, 2018 | |
| F5 Big Ip | f5-bigip-upgrade-latest | Jun 17, 2026 | Mar 19, 2018 | |
| Freebsd | freebsd-upgrade-base-11_1-release-p7freebsd-upgrade-base-10_4-release-p6freebsd-upgrade-base-10_3-release-p27freebsd-upgrade-package-ntpfreebsd-upgrade-package-ntp-devel | May 6, 2018 | Feb 28, 2018 | |
| Gentoo Linux | gentoo-linux-upgrade-net-misc-ntp | May 29, 2018 | Mar 6, 2018 | |
| Hpux | — | hpux-update-ntp | Dec 9, 2019 | Mar 6, 2018 |
| Ibm Aix | ibm-aix-ntp_advisory10ibm-aix-ntp_advisory11 | Aug 16, 2018 | Mar 6, 2018 | |
| Ntp | ntp-upgrade-4_2_8ntp-upgrade-4_3_92 | Feb 23, 2023 | Mar 6, 2018 | |
| Oracle Solaris | oracle-solaris-11-3-upgrade-service-network-ntp-4-2-8-11-0-175-3-31-0-4-0oracle-solaris-11-4-upgrade-service-network-ntp-4-2-8-12-11-4-8-0-1-3-0 | Apr 18, 2018 | Mar 6, 2018 | |
| Redhat_linux | no-fix-redhat-rpm-package | Jul 9, 2025 | Mar 6, 2018 | |
| Suse | — | suse-upgrade-ntpsuse-upgrade-ntp-doc | Mar 27, 2018 | Mar 6, 2018 |
| Ubuntu | ubuntu-upgrade-ntp | Nov 19, 2024 | Mar 6, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub