CVE-2016-7426 — Uncontrolled Resource Consumption in HPE Hpux-ntp
Severity
7.5HIGHNVD
EPSS
11.7%
top 6.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 13
Latest updateMay 13
Description
NTP before 4.2.8p9 rate limits responses received from the configured sources when rate limiting for all associations is enabled, which allows remote attackers to cause a denial of service (prevent responses from the sources) by sending responses with a spoofed source address.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6
Affected Packages6 packages
Also affects: Ubuntu Linux 12.04, Enterprise Linux 7.3, 7.4, 7.6, 7.7, 7.5
🔴Vulnerability Details
4📋Vendor Advisories
6Cisco▶
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: November 2016↗2016-11-23