Severity
6.5MEDIUMNVD
OSV5.9
EPSS
2.2%
top 15.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 13
Latest updateMay 14

Description

The control mode (mode 6) functionality in ntpd in NTP before 4.2.8p9 allows remote attackers to set or unset traps via a crafted control mode packet.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:LExploitability: 3.9 | Impact: 2.5

Affected Packages4 packages

debiandebian/ntp< ntp 1:4.2.8p9+dfsg-1 (bullseye)
Debianntp/ntp< 1:4.2.8p9+dfsg-1
Ubuntuntp/ntp< 1:4.2.6.p5+dfsg-3ubuntu2.14.04.11+1
NVDntp/ntp4.2.8

🔴Vulnerability Details

3
GHSA
GHSA-x99c-5hjh-5p3r: The control mode (mode 6) functionality in ntpd in NTP before 42022-05-14
OSV
ntp vulnerabilities2017-07-05
OSV
CVE-2016-9310: The control mode (mode 6) functionality in ntpd in NTP before 42017-01-13

📋Vendor Advisories

7
Ubuntu
NTP vulnerabilities2019-01-23
Ubuntu
NTP vulnerabilities2017-07-05
BSD
FreeBSD-SA-16:39.ntp: Multiple vulnerabilities of ntp2016-12-22
Cisco
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: November 20162016-11-23
Red Hat
ntp: Mode 6 unauthenticated trap information disclosure and DDoS vector2016-11-21

💬Community

2
Bugzilla
CVE-2016-9310 ntp: Mode 6 unauthenticated trap information disclosure and DDoS vector2016-11-22
Bugzilla
CVE-2016-7426 CVE-2016-7429 CVE-2016-7433 CVE-2016-9310 CVE-2016-9311 ntp: various flaws [fedora-all]2016-11-22