Lucene search

K
cve[email protected]CVE-2013-5211
HistoryJan 02, 2014 - 2:59 p.m.

CVE-2013-5211

2014-01-0214:59:03
CWE-20
web.nvd.nist.gov
303
cve-2013-5211
ntp
monlist
ntpd
denial of service
traffic amplification
req_mon_getlist
req_mon_getlist_1
nvd

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

5.7 Medium

AI Score

Confidence

High

0.967 High

EPSS

Percentile

99.7%

The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service (traffic amplification) via forged (1) REQ_MON_GETLIST or (2) REQ_MON_GETLIST_1 requests, as exploited in the wild in December 2013.

Affected configurations

NVD
Node
opensuseopensuseMatch11.4
Node
ntpntpRange<4.2.7
OR
ntpntpMatch4.2.7-
OR
ntpntpMatch4.2.7p0
OR
ntpntpMatch4.2.7p1
OR
ntpntpMatch4.2.7p10
OR
ntpntpMatch4.2.7p11
OR
ntpntpMatch4.2.7p12
OR
ntpntpMatch4.2.7p13
OR
ntpntpMatch4.2.7p14
OR
ntpntpMatch4.2.7p15
OR
ntpntpMatch4.2.7p16
OR
ntpntpMatch4.2.7p17
OR
ntpntpMatch4.2.7p18
OR
ntpntpMatch4.2.7p19
OR
ntpntpMatch4.2.7p2
OR
ntpntpMatch4.2.7p20
OR
ntpntpMatch4.2.7p21
OR
ntpntpMatch4.2.7p22
OR
ntpntpMatch4.2.7p23
OR
ntpntpMatch4.2.7p24
OR
ntpntpMatch4.2.7p25
OR
ntpntpMatch4.2.7p3
OR
ntpntpMatch4.2.7p4
OR
ntpntpMatch4.2.7p5
OR
ntpntpMatch4.2.7p6
OR
ntpntpMatch4.2.7p7
OR
ntpntpMatch4.2.7p8
OR
ntpntpMatch4.2.7p9
Node
oraclelinuxMatch6-
OR
oraclelinuxMatch7-
CPENameOperatorVersion
opensuse:opensuseopensuseeq11.4

References

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

5.7 Medium

AI Score

Confidence

High

0.967 High

EPSS

Percentile

99.7%