CVE-2020-11868

ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronization via a server mode packet with a spoofed source IP address, because transmissions are rescheduled even when a packet lacks a valid origin timestamp.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
mitreCNA
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.0/AC:H/AV:N/A:H/C:N/I:N/PR:N/S:U/UI:N
CVEADP
---
---
CISA-ADPADP
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 68%
VendorProductVersion
ntpntp
𝑥
≤ 4.2.7
ntpntp
4.3.98 ≤
𝑥
< 4.3.100
ntpntp
4.2.8
ntpntp
4.2.8:p1
ntpntp
4.2.8:p1-beta1
ntpntp
4.2.8:p1-beta2
ntpntp
4.2.8:p1-beta3
ntpntp
4.2.8:p1-beta4
ntpntp
4.2.8:p1-beta5
ntpntp
4.2.8:p1-rc1
ntpntp
4.2.8:p1-rc2
ntpntp
4.2.8:p10
ntpntp
4.2.8:p11
ntpntp
4.2.8:p12
ntpntp
4.2.8:p13
ntpntp
4.2.8:p2
ntpntp
4.2.8:p2-rc1
ntpntp
4.2.8:p2-rc2
ntpntp
4.2.8:p2-rc3
ntpntp
4.2.8:p3
ntpntp
4.2.8:p3-rc1
ntpntp
4.2.8:p3-rc2
ntpntp
4.2.8:p3-rc3
ntpntp
4.2.8:p4
ntpntp
4.2.8:p5
ntpntp
4.2.8:p6
ntpntp
4.2.8:p7
ntpntp
4.2.8:p8
ntpntp
4.2.8:p9
redhatenterprise_linux
7.0
netappdata_ontap
-
netapphci_management_node
-
netappsolidfire
-
netappvasa_provider_for_clustered_data_ontap
7.2 ≤
netappvasa_provider_for_clustered_data_ontap
7.2 ≤
netappvirtual_storage_console
7.2 ≤
netappclustered_data_ontap
-
netapphci_storage_node_firmware
-
netappfabric-attached_storage_8300_firmware
-
netappfabric-attached_storage_8700_firmware
-
netappfabric-attached_storage_a400_firmware
-
netappall_flash_fabric-attached_storage_8300_firmware
-
netappall_flash_fabric-attached_storage_8700_firmware
-
netappall_flash_fabric-attached_storage_a400_firmware
-
debiandebian_linux
8.0
opensuseleap
15.1
opensuseleap
15.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
ntp
bullseye
1:4.2.8p15+dfsg-1
fixed
buster
no-dsa
stretch
no-dsa
ntpsec
bullseye
1.2.0+dfsg1-4
fixed
buster
no-dsa
stretch
no-dsa
bookworm
1.2.2+dfsg1-1+deb12u1
fixed
bookworm (security)
1.2.2+dfsg1-1+deb12u1
fixed
sid
1.2.3+dfsg1-3
fixed
trixie
1.2.3+dfsg1-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ntp
noble
dne
mantic
dne
lunar
dne
kinetic
dne
jammy
needs-triage
impish
ignored
hirsute
ignored
groovy
ignored
focal
needs-triage
eoan
ignored
bionic
needs-triage
xenial
needs-triage
trusty
needs-triage
ntpsec
noble
needs-triage
mantic
ignored
lunar
ignored
kinetic
ignored
jammy
needs-triage
impish
ignored
hirsute
ignored
groovy
ignored
focal
needs-triage
eoan
ignored
bionic
needs-triage
xenial
dne
trusty
dne