CVE-2020-11868
published 2020-04-17CVE-2020-11868: ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronization via a server mode packet with a…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.08%
79.5th percentile
ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronization via a server mode packet with a spoofed source IP address, because transmissions are rescheduled even when a packet lacks a valid origin timestamp.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | ntp | < ntp 1:4.2.8p14+dfsg-1 (bullseye) | ntp 1:4.2.8p14+dfsg-1 (bullseye) |
| debian | ntpsec | < ntp 1:4.2.8p14+dfsg-1 (bullseye) | ntp 1:4.2.8p14+dfsg-1 (bullseye) |
| netapp | vasa_provider_for_clustered_data_ontap | >= 7.2 | — |
| netapp | virtual_storage_console | >= 7.2 | — |
| ntp | ntp | <= 4.2.7 | — |
| ntp | ntp | — | — |
| ntp | ntp | >= 0 < 1:4.2.8p14+dfsg-1 | 1:4.2.8p14+dfsg-1 |
| ntp | ntp | >= 4.3.98 < 4.3.100 | 4.3.100 |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-57qq-hwp2-xmcj: ntpd in ntp before 4
ghsa_unreviewed·2022-05-24
CVE-2020-11868 [MEDIUM] CWE-346 GHSA-57qq-hwp2-xmcj: ntpd in ntp before 4
ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronization via a server mode packet with a spoofed source IP address, because transmissions are rescheduled even when a packet lacks a valid origin timestamp.
OSV
CVE-2020-11868: ntpd in ntp before 4
osv·2020-04-17·CVSS 7.5
CVE-2020-11868 [HIGH] CVE-2020-11868: ntpd in ntp before 4
ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronization via a server mode packet with a spoofed source IP address, because transmissions are rescheduled even when a packet lacks a valid origin timestamp.
CISA ICS
Hitachi Energy AFF66x
cisa_ics·2023-08-22·CVSS 7.4
[HIGH] Hitachi Energy AFF66x
ICS Advisory
##
Hitachi Energy AFF66x
Release DateAugust 22, 2023
Alert CodeICSA-23-234-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.6
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Hitachi Energy
- Equipment: AFF66x
- Vulnerabilities: Cross-site Scripting, Use of Insufficiently Random Values, Origin Validation Error, Integer Overflow or Wraparound, Uncontrolled Resource Consumption, NULL Pointer Dereference
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to compromise availability, integrity, and confidentiality of the targeted devices.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Hitachi Energy reports these vulnerabilities affect the following AFF660/665 products:
- AFF660/665
Red Hat
ntp: DoS on client ntpd using server mode packet
vendor_redhat·2020-03-03·CVSS 7.5
CVE-2020-11868 [HIGH] CWE-400 ntp: DoS on client ntpd using server mode packet
ntp: DoS on client ntpd using server mode packet
ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronization via a server mode packet with a spoofed source IP address, because transmissions are rescheduled even when a packet lacks a valid origin timestamp.
A flaw was found in the Network Time Protocol (NTP), where a security issue exists that allows an off-path attacker to prevent the Network Time Protocol daemon (ntpd) from synchronizing with NTP servers not using authentication. A server mode packet with a spoofed source address sent to the client ntpd causes the next transmission to be rescheduled, even if the packet does not have a valid origin timestamp. If the packet is sent to the client frequently enough, it stops poll
Debian
CVE-2020-11868: ntp - ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker...
vendor_debian·2020·CVSS 7.5
CVE-2020-11868 [HIGH] CVE-2020-11868: ntp - ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker...
ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronization via a server mode packet with a spoofed source IP address, because transmissions are rescheduled even when a packet lacks a valid origin timestamp.
Scope: local
bullseye: resolved (fixed in 1:4.2.8p14+dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-11868 ntp: DoS on client ntpd using server mode packet [fedora-all]
bugzilla·2020-04-16·CVSS 7.5
CVE-2020-11868 [HIGH] CVE-2020-11868 ntp: DoS on client ntpd using server mode packet [fedora-all]
CVE-2020-11868 ntp: DoS on client ntpd using server mode packet [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions
Bugzilla
CVE-2020-11868 ntp: DoS on client ntpd using server mode packet
bugzilla·2019-06-03·CVSS 7.5
CVE-2020-11868 [HIGH] CVE-2020-11868 ntp: DoS on client ntpd using server mode packet
CVE-2020-11868 ntp: DoS on client ntpd using server mode packet
A vulnerability was found in NTP. A security issue which enables an off-path attacker to prevent ntpd from synchronizing with NTP servers not using authentication. A server mode packet with spoofed source address sent to the client ntpd causes the next transmission to be rescheduled, even if the packet doesn't have a valid origin timestamp. If the packet is sent to the client frequently enough, it will stop polling the server and not be able to synchronize with it.
Discussion:
*** Bug 1716661 has been marked as a duplicate of this bug. ***
---
External References:
http://support.ntp.org/bin/view/Main/NtpBug3592
---
Mitigation:
Use authentication with symmetric keys.
---
Created ntp tracking bugs for this issue:
Aff
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00044.htmlhttp://support.ntp.org/bin/view/Main/NtpBug3592https://bugzilla.redhat.com/show_bug.cgi?id=1716665https://lists.debian.org/debian-lts-announce/2020/05/msg00004.htmlhttps://security.gentoo.org/glsa/202007-12https://security.netapp.com/advisory/ntap-20200424-0002/https://www.oracle.com//security-alerts/cpujul2021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00044.htmlhttp://support.ntp.org/bin/view/Main/NtpBug3592https://bugzilla.redhat.com/show_bug.cgi?id=1716665https://lists.debian.org/debian-lts-announce/2020/05/msg00004.htmlhttps://security.gentoo.org/glsa/202007-12https://security.netapp.com/advisory/ntap-20200424-0002/https://www.oracle.com//security-alerts/cpujul2021.html
2020-04-17
Published