7.4
CVE-2020-13817
- EPSS 0.38%
- Veröffentlicht 04.06.2020 13:15:11
- Zuletzt bearbeitet 05.05.2025 17:15:59
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows remote attackers to cause a denial of service (daemon exit or system time change) by predicting transmit timestamps for use in spoofed packets. The victim must be relying on unauthenticated IPv4 time sources. There must be an off-path attacker who can query time from the victim's ntpd instance.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Netapp ≫ Cloud Backup Version-
Netapp ≫ Clustered Data Ontap Version-
Netapp ≫ Data Ontap Version- SwPlatform7-mode
Netapp ≫ Element Software Version-
Netapp ≫ Hci Management Node Version-
Netapp ≫ Ontap Tools Version- SwPlatformvmware_vsphere
Netapp ≫ Steelstore Cloud Integrated Storage Version-
Netapp ≫ Hci Compute Node Firmware Version-
Netapp ≫ H410c Firmware Version-
Netapp ≫ H300s Firmware Version-
Netapp ≫ H500s Firmware Version-
Netapp ≫ H700s Firmware Version-
Netapp ≫ H300e Firmware Version-
Netapp ≫ H500e Firmware Version-
Netapp ≫ H700e Firmware Version-
Netapp ≫ H410s Firmware Version-
Fujitsu ≫ M10-1 Firmware Version < xcp2410
Fujitsu ≫ M10-4 Firmware Version < xcp2410
Fujitsu ≫ M10-4s Firmware Version < xcp2410
Fujitsu ≫ M12-1 Firmware Version < xcp2410
Fujitsu ≫ M12-2 Firmware Version < xcp2410
Fujitsu ≫ M12-2s Firmware Version < xcp2410
Fujitsu ≫ M10-4 Firmware Version < xcp3110
Fujitsu ≫ M10-4s Firmware Version < xcp3110
Fujitsu ≫ M12-1 Firmware Version < xcp3110
Fujitsu ≫ M12-2 Firmware Version < xcp3110
Fujitsu ≫ M12-2s Firmware Version < xcp3110
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.38% | 0.583 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.4 | 2.2 | 5.2 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
|
nvd@nist.gov | 5.8 | 8.6 | 4.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:P
|
134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.4 | 2.2 | 5.2 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
|
cve@mitre.org | 5.9 | 2.2 | 3.6 |
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-330 Use of Insufficiently Random Values
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.