Lucene search

K
f5F5F5:K04912972
HistoryApr 10, 2018 - 12:00 a.m.

K04912972 : NTP vulnerability CVE-2018-7185

2018-04-1000:00:00
my.f5.com
22

8.1 High

AI Score

Confidence

High

0.033 Low

EPSS

Percentile

91.3%

Security Advisory Description

The protocol engine in ntp 4.2.6 before 4.2.8p11 allows a remote attackers to cause a denial of service (disruption) by continually sending a packet with a zero-origin timestamp and source IP address of the “other side” of an interleaved association causing the victim ntpd to reset its association. (CVE-2018-7185)

Impact

An attacker can exploit this vulnerability using crafted packets to cause the affected ntpdto reset its peer association. Only F5 products configured with authenticated interleaved peer association on the network time protocol (NTP) service are vulnerable, and this is a non-default configuration.