CVE-2016-9311 — NULL Pointer Dereference in NTP
Severity
5.9MEDIUMNVD
EPSS
4.8%
top 10.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 13
Latest updateMay 14
Description
ntpd in NTP before 4.2.8p9, when the trap service is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted packet.
CVSS vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 2.2 | Impact: 3.6
Affected Packages4 packages
🔴Vulnerability Details
3📋Vendor Advisories
7Cisco▶
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: November 2016↗2016-11-23