Back

MEDIUM

ntp: ntpd allows remote attackers to prevent a broadcast client from synchronizing its clock

Published May 6, 2020

Description

ntpd in ntp 4.2.8p10, 4.2.8p11, 4.2.8p12 and 4.2.8p13 allow remote attackers to prevent a broadcast client from synchronizing its clock with a broadcast NTP server via soofed mode 3 and mode 5 packets. The attacker must either be a part of the same broadcast network or control a slave in that broadcast network that can capture certain required packets on the attacker's behalf and send them to the attacker.

Affected products

Remediation

Red Hat statement

As per the researcher this issue only affects NTP versions 4.2.8p10 through 4.2.8p13, which are not shipped with any Red Hat products, therefore they are not affected by this flaw.

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 6, 2020
Updated Aug 5, 2024
Reserved Mar 23, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date May 6, 2020
ENISA EUVD
Assigner mitre
Published May 6, 2020
Updated Aug 5, 2024
Exploited since n/a
EUVD-2018-20563