Lucene search

K
cve[email protected]CVE-2009-3563
HistoryDec 09, 2009 - 6:30 p.m.

CVE-2009-3563

2009-12-0918:30:00
web.nvd.nist.gov
106
cve-2009-3563
ntpd
ntp
denial of service
security vulnerability
mode_private
spoofed packet

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:P/A:P

6.8 Medium

AI Score

Confidence

High

0.965 High

EPSS

Percentile

99.6%

ntp_request.c in ntpd in NTP before 4.2.4p8, and 4.2.5, allows remote attackers to cause a denial of service (CPU and bandwidth consumption) by using MODE_PRIVATE to send a spoofed (1) request or (2) response packet that triggers a continuous exchange of MODE_PRIVATE error responses between two NTP daemons.

Affected configurations

NVD
Node
ntpntpRange≀4.2.2p4
OR
ntpntpMatch4.0.72
OR
ntpntpMatch4.0.73
OR
ntpntpMatch4.0.90
OR
ntpntpMatch4.0.91
OR
ntpntpMatch4.0.92
OR
ntpntpMatch4.0.93
OR
ntpntpMatch4.0.94
OR
ntpntpMatch4.0.95
OR
ntpntpMatch4.0.96
OR
ntpntpMatch4.0.97
OR
ntpntpMatch4.0.98
OR
ntpntpMatch4.0.99
OR
ntpntpMatch4.1.0
OR
ntpntpMatch4.1.2
OR
ntpntpMatch4.2.0
OR
ntpntpMatch4.2.2
OR
ntpntpMatch4.2.2p1
OR
ntpntpMatch4.2.2p2
OR
ntpntpMatch4.2.2p3
OR
ntpntpMatch4.2.5

References

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:P/A:P

6.8 Medium

AI Score

Confidence

High

0.965 High

EPSS

Percentile

99.6%