ZeroHour

CVE-2020-15025

CVSS 3.1
4.9 medium
EPSS
3%p88
Published
()
Modified
Description

ntpd in ntp 4.2.8 before 4.2.8p15 and 4.3.x before 4.3.101 allows remote attackers to cause a denial of service (memory consumption) by sending packets, because memory is not freed in situations where a CMAC key is used and associated with a CMAC algorithm in the ntp.keys file.

Vendors
ntpopensusenetapporacle
Products
ntp, leap, cloud backup, steelstore cloud integrated storage, 8300 firmware, 8700 firmware, a400 firmware, h410c firmware, h300s firmware, h500s firmware, h700s firmware, h300e firmware
Weakness
CWE-401
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.