ZeroHour

CVE-2018-7185

CVSS 3.1
7.5 high
EPSS
9%p95
Published
()
Modified
Description

The protocol engine in ntp 4.2.6 before 4.2.8p11 allows a remote attackers to cause a denial of service (disruption) by continually sending a packet with a zero-origin timestamp and source IP address of the "other side" of an interleaved association causing the victim ntpd to reset its association.

Vendors
ntpsynologycanonicalnetapphpeoracle
Products
ntp, router manager, skynas, virtual diskstation manager, diskstation manager, vs960hd firmware, ubuntu linux, hci, solidfire, hpux-ntp, fujitsu m10-1 firmware, fujitsu m10-4 firmware
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.