PT-2019-6438 · Ntt+7 · Ntp+7

Published

2019-05-30

·

Updated

2025-05-05

·

CVE-2020-13817

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions ntp versions 4.2.8 through 4.2.8p14 ntp versions 4.3.x through 4.3.100
Description The issue is related to the implementation of the NTP protocol, specifically with the use of insufficiently random values. This allows a remote attacker to cause a denial of service, either by exiting the daemon or changing the system time, by predicting transmit timestamps for use in spoofed packets. The victim must be relying on unauthenticated IPv4 time sources, and there must be an off-path attacker who can query time from the victim's ntpd instance.
Recommendations For ntp versions 4.2.8 through 4.2.8p14, update to version 4.2.8p15 or later to resolve the issue. For ntp versions 4.3.x through 4.3.100, update to version 4.3.101 or later to resolve the issue. As a temporary workaround, consider restricting access to unauthenticated IPv4 time sources to minimize the risk of exploitation.

Fix

DoS

Use of Insufficiently Random Values

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-1552
ALT-PU-2020-1678
BDU:2024-07287
CESA-2020_2663
CVE-2020-13817
OPENSUSE-SU-2020:0934-1
OPENSUSE-SU-2020:1007-1
OPENSUSE-SU-2020_0934-1
OPENSUSE-SU-2020_1007-1
OPENSUSE-SU-2024:11102-1
RHSA-2020:2663
RHSA-2020_2663
SUSE-SU-2020:14415-1
SUSE-SU-2020:1805-1
SUSE-SU-2020:1823-1

Affected Products

Alt Linux
Astra Linux
Centos
Ibm Aix
Red Hat
Red Os
Suse
Ntp