ntpd in ntp 4.2.8p10, 4.2.8p11, 4.2.8p12 and 4.2.8p13 allow remote attackers to prevent a broadcast client from synchronizing its clock with a broadcast NTP server via soofed mode 3 and mode 5 packets. The attacker must either be a part of the same broadcast network or control a slave in that broadcast network that can capture certain required packets on the attacker's behalf and send them to the attacker.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade ntp | Jul 30, 2024 | May 6, 2020 |
| Ntp | — | Upgrade to the latest version of NTP | Feb 23, 2023 | May 6, 2020 |
| Oracle Solaris | — | Upgrade service/network/ntp to version 4.2.8.14-11.4.24.0.1.75.1 on Solaris 11.4 | Jan 19, 2021 | May 6, 2020 |
| Suse | — | Upgrade ntp-docUpgrade ntp | Jul 1, 2020 | May 6, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub