Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-9042

Опубликовано: 04 июн. 2018
Источник: nvd
CVSS3: 3.7
CVSS3: 5.9
CVSS2: 4.3
EPSS Низкий

Описание

An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticated network packet can be used to reset the expected origin timestamp for target peers. Legitimate replies from targeted peers will fail the origin timestamp check (TEST2) causing the reply to be dropped and creating a denial of service condition.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ntp:ntp:4.2.8:p9:*:*:*:*:*:*
Конфигурация 2

Одно из

cpe:2.3:o:freebsd:freebsd:10.0:*:*:*:*:*:*:*
cpe:2.3:o:freebsd:freebsd:11.0:*:*:*:*:*:*:*
Конфигурация 3
cpe:2.3:a:hpe:hpux-ntp:*:*:*:*:*:*:*:*
Версия до c.4.2.8.4.0 (исключая)
Конфигурация 4

Одновременно

cpe:2.3:o:siemens:simatic_net_cp_443-1_opc_ua_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_net_cp_443-1_opc_ua:-:*:*:*:*:*:*:*

EPSS

Процентиль: 89%
0.04844
Низкий

3.7 Low

CVSS3

5.9 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 7 лет назад

An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticated network packet can be used to reset the expected origin timestamp for target peers. Legitimate replies from targeted peers will fail the origin timestamp check (TEST2) causing the reply to be dropped and creating a denial of service condition.

CVSS3: 5.9
redhat
почти 9 лет назад

An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticated network packet can be used to reset the expected origin timestamp for target peers. Legitimate replies from targeted peers will fail the origin timestamp check (TEST2) causing the reply to be dropped and creating a denial of service condition.

CVSS3: 5.9
debian
больше 7 лет назад

An exploitable denial of service vulnerability exists in the origin ti ...

CVSS3: 5.9
github
больше 3 лет назад

An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticated network packet can be used to reset the expected origin timestamp for target peers. Legitimate replies from targeted peers will fail the origin timestamp check (TEST2) causing the reply to be dropped and creating a denial of service condition.

suse-cvrf
почти 9 лет назад

Security update for ntp

EPSS

Процентиль: 89%
0.04844
Низкий

3.7 Low

CVSS3

5.9 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-20