Severity
4.3MEDIUMNVD
OSV5.9
EPSS
5.3%
top 9.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 13
Latest updateMay 14

Description

ntpd in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (reject broadcast mode packets) via the poll interval in a broadcast packet.

CVSS vector

CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LExploitability: 2.8 | Impact: 1.4

Affected Packages4 packages

debiandebian/ntp< ntp 1:4.2.8p9+dfsg-1 (bullseye)
Debianntp/ntp< 1:4.2.8p9+dfsg-1
Ubuntuntp/ntp< 1:4.2.6.p5+dfsg-3ubuntu2.14.04.11+1
NVDntp/ntp4.2.8

🔴Vulnerability Details

3
GHSA
GHSA-jf98-49c3-8w82: ntpd in NTP before 42022-05-14
OSV
ntp vulnerabilities2017-07-05
OSV
CVE-2016-7428: ntpd in NTP before 42017-01-13

📋Vendor Advisories

7
Ubuntu
NTP vulnerabilities2019-01-23
Ubuntu
NTP vulnerabilities2017-07-05
BSD
FreeBSD-SA-16:39.ntp: Multiple vulnerabilities of ntp2016-12-22
Cisco
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: November 20162016-11-23
Red Hat
ntp: Broadcast Mode Poll Interval Enforcement DoS2016-11-21

💬Community

2
Bugzilla
CVE-2016-7428 ntp: Broadcast Mode Poll Interval Enforcement DoS2016-11-22
Bugzilla
CVE-2016-7426 CVE-2016-7429 CVE-2016-7433 CVE-2016-9310 CVE-2016-9311 ntp: various flaws [fedora-all]2016-11-22