Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-9042

Опубликовано: 04 июн. 2018
Источник: nvd
CVSS3: 3.7
CVSS3: 5.9
CVSS2: 4.3
EPSS Низкий

Описание

An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticated network packet can be used to reset the expected origin timestamp for target peers. Legitimate replies from targeted peers will fail the origin timestamp check (TEST2) causing the reply to be dropped and creating a denial of service condition.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ntp:ntp:4.2.8:p9:*:*:*:*:*:*
Конфигурация 2

Одно из

cpe:2.3:o:freebsd:freebsd:10.0:*:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:11.0:*:*:*:*:*:*:*
Конфигурация 3
cpe:2.3:a:hpe:hpux-ntp:*:*:*:*:*:*:*:*
Версия до c.4.2.8.4.0 (исключая)
Конфигурация 4

Одновременно

cpe:2.3:o:siemens:simatic_net_cp_443-1_opc_ua_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_net_cp_443-1_opc_ua:-:*:*:*:*:*:*:*

EPSS

Процентиль: 89%
0.0391
Низкий

3.7 Low

CVSS3

5.9 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 5.9
ubuntu
около 8 лет назад

An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticated network packet can be used to reset the expected origin timestamp for target peers. Legitimate replies from targeted peers will fail the origin timestamp check (TEST2) causing the reply to be dropped and creating a denial of service condition.

CVSS3: 5.9
redhat
больше 9 лет назад

An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticated network packet can be used to reset the expected origin timestamp for target peers. Legitimate replies from targeted peers will fail the origin timestamp check (TEST2) causing the reply to be dropped and creating a denial of service condition.

CVSS3: 5.9
debian
около 8 лет назад

An exploitable denial of service vulnerability exists in the origin ti ...

CVSS3: 5.9
github
больше 4 лет назад

An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticated network packet can be used to reset the expected origin timestamp for target peers. Legitimate replies from targeted peers will fail the origin timestamp check (TEST2) causing the reply to be dropped and creating a denial of service condition.

suse-cvrf
больше 9 лет назад

Security update for ntp

EPSS

Процентиль: 89%
0.0391
Низкий

3.7 Low

CVSS3

5.9 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-20