5.3

CVE-2016-7431

NTP before 4.2.8p9 allows remote attackers to bypass the origin timestamp protection mechanism via an origin timestamp of zero.  NOTE: this vulnerability exists because of a CVE-2015-8138 regression.

Data is provided by the National Vulnerability Database (NVD)
NtpNtp Version4.2.8 Updatep8
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 19.91% 0.952
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://nwtime.org/ntp428p9_release/
Vendor Advisory
Release Notes
https://www.kb.cert.org/vuls/id/633847
Third Party Advisory
US Government Resource
http://support.ntp.org/bin/view/Main/NtpBug3102
Vendor Advisory
Issue Tracking
Mitigation