CVE-2016-2516 — Improper Input Validation in NTP
Severity
5.3MEDIUMNVD
OSV6.5
EPSS
3.6%
top 12.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 30
Latest updateMay 17
Description
NTP before 4.2.8p7 and 4.3.x before 4.3.92, when mode7 is enabled, allows remote attackers to cause a denial of service (ntpd abort) by using the same IP address multiple times in an unconfig directive.
CVSS vector
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.6 | Impact: 3.6
Affected Packages4 packages
🔴Vulnerability Details
5📋Vendor Advisories
8Cisco▶
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: April 2016↗2016-04-28