CVE-2016-4954
—CVSS 3.1
7.5 high
EPSS
13%p96
Published
()
Modified
Description
The process_packet function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (peer-variable modification) by sending spoofed packets from many source IP addresses in a certain scenario, as demonstrated by triggering an incorrect leap indication.
- Vendors
- ntporaclesuseopensusesiemens
- Products
- ntp, solaris, manager, manager proxy, openstack cloud, leap, opensuse, linux enterprise desktop, linux enterprise server, simatic net cp 443-1 opc ua firmware, tim 4r-ie firmware, tim 4r-ie dnp3 firmware
- Weakness
- CWE-362
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.