ZeroHour

CVE-2020-11868

CVSS 3.1
7.5 high
EPSS
2%p81
Published
()
Modified
Description

ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronization via a server mode packet with a spoofed source IP address, because transmissions are rescheduled even when a packet lacks a valid origin timestamp.

Vendors
ntpredhatnetappdebianopensuse
Products
ntp, enterprise linux, data ontap, hci management node, solidfire, vasa provider for clustered data ontap, virtual storage console, clustered data ontap, hci storage node firmware, fabric-attached storage 8300 firmware, fabric-attached storage 8700 firmware, fabric-attached storage a400 firmware
Weakness
CWE-346
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.