7.5

CVE-2018-7185

The protocol engine in ntp 4.2.6 before 4.2.8p11 allows a remote attackers to cause a denial of service (disruption) by continually sending a packet with a zero-origin timestamp and source IP address of the "other side" of an interleaved association causing the victim ntpd to reset its association.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NtpNtp Version >= 4.2.6 < 4.2.8
NtpNtp Version4.2.8 Update-
NtpNtp Version4.2.8 Updatep1
NtpNtp Version4.2.8 Updatep1-beta1
NtpNtp Version4.2.8 Updatep1-beta2
NtpNtp Version4.2.8 Updatep1-beta3
NtpNtp Version4.2.8 Updatep1-beta4
NtpNtp Version4.2.8 Updatep1-beta5
NtpNtp Version4.2.8 Updatep1-rc1
NtpNtp Version4.2.8 Updatep1-rc2
NtpNtp Version4.2.8 Updatep10
NtpNtp Version4.2.8 Updatep2
NtpNtp Version4.2.8 Updatep2-rc1
NtpNtp Version4.2.8 Updatep2-rc2
NtpNtp Version4.2.8 Updatep2-rc3
NtpNtp Version4.2.8 Updatep3
NtpNtp Version4.2.8 Updatep3-rc1
NtpNtp Version4.2.8 Updatep3-rc2
NtpNtp Version4.2.8 Updatep3-rc3
NtpNtp Version4.2.8 Updatep4
NtpNtp Version4.2.8 Updatep5
NtpNtp Version4.2.8 Updatep6
NtpNtp Version4.2.8 Updatep7
NtpNtp Version4.2.8 Updatep8
NtpNtp Version4.2.8 Updatep9
SynologyRouter Manager Version >= 1.1 < 1.1.6-6931-3
SynologySkynas Version < 6.1.5-15254
SynologyVirtual Diskstation Manager Version < 6.1.6-15266
SynologyDiskstation Manager Version >= 5.2 < 6.1.6-15266
SynologyVs960hd Firmware Version < 2.2.3-1505
   SynologyVs960hd Version-
CanonicalUbuntu Linux Version12.04 SwEditionesm
CanonicalUbuntu Linux Version14.04 SwEditionlts
CanonicalUbuntu Linux Version16.04 SwEditionlts
CanonicalUbuntu Linux Version17.10
CanonicalUbuntu Linux Version18.04 SwEditionlts
NetappHci Version-
NetappSolidfire Version-
HpeHpux-ntp Version < c.4.2.8.4.0
OracleFujitsu M10-1 Firmware Version < xcp2361
   OracleFujitsu M10-1 Version-
OracleFujitsu M10-4 Firmware Version < xcp2361
   OracleFujitsu M10-4 Version-
OracleFujitsu M10-4s Firmware Version < xcp2361
   OracleFujitsu M10-4s Version-
OracleFujitsu M12-1 Firmware Version < xcp2361
   OracleFujitsu M12-1 Version-
OracleFujitsu M12-2 Firmware Version < xcp2361
   OracleFujitsu M12-2 Version-
OracleFujitsu M12-2s Firmware Version < xcp2361
   OracleFujitsu M12-2s Version-
OracleFujitsu M10-1 Firmware Version < xcp3070
   OracleFujitsu M10-1 Version-
OracleFujitsu M10-4 Firmware Version < xcp3070
   OracleFujitsu M10-4 Version-
OracleFujitsu M10-4s Firmware Version < xcp3070
   OracleFujitsu M10-4s Version-
OracleFujitsu M12-1 Firmware Version < xcp3070
   OracleFujitsu M12-1 Version-
OracleFujitsu M12-2 Firmware Version < xcp3070
   OracleFujitsu M12-2 Version-
OracleFujitsu M12-2s Firmware Version < xcp3070
   OracleFujitsu M12-2s Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 16.93% 0.948
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P