CVE-2016-7431 — Improper Input Validation in NTP
Severity
5.3MEDIUMNVD
OSV5.9
EPSS
18.6%
top 4.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 13
Latest updateMay 13
Description
NTP before 4.2.8p9 allows remote attackers to bypass the origin timestamp protection mechanism via an origin timestamp of zero. NOTE: this vulnerability exists because of a CVE-2015-8138 regression.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4
Affected Packages4 packages
🔴Vulnerability Details
3📋Vendor Advisories
7Cisco▶
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: November 2016↗2016-11-23