Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-13817


ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows remote attackers to cause a denial of service (daemon exit or system time change) by predicting transmit timestamps for use in spoofed packets. The victim must be relying on unauthenticated IPv4 time sources. There must be an off-path attacker who can query time from the victim's ntpd instance.


Published

2020-06-04T13:15:11.053

Last Modified

2025-05-05T17:15:59.030

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.4 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

4.9

Weaknesses
  • Type: Primary
    CWE-330
  • Type: Secondary
    CWE-330

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ntp ntp < 4.2.8 Yes
Application ntp ntp < 4.3.100 Yes
Application ntp ntp 4.2.8 Yes
Application ntp ntp 4.2.8 Yes
Application ntp ntp 4.2.8 Yes
Application ntp ntp 4.2.8 Yes
Application ntp ntp 4.2.8 Yes
Application ntp ntp 4.2.8 Yes
Application ntp ntp 4.2.8 Yes
Application ntp ntp 4.2.8 Yes
Application ntp ntp 4.2.8 Yes
Application ntp ntp 4.2.8 Yes
Application ntp ntp 4.2.8 Yes
Application ntp ntp 4.2.8 Yes
Application ntp ntp 4.2.8 Yes
Application ntp ntp 4.2.8 Yes
Application ntp ntp 4.2.8 Yes
Application ntp ntp 4.2.8 Yes
Application ntp ntp 4.2.8 Yes
Application ntp ntp 4.2.8 Yes
Application ntp ntp 4.2.8 Yes
Application ntp ntp 4.2.8 Yes
Application ntp ntp 4.2.8 Yes
Application ntp ntp 4.2.8 Yes
Application ntp ntp 4.2.8 Yes
Application ntp ntp 4.2.8 Yes
Application ntp ntp 4.2.8 Yes
Application ntp ntp 4.2.8 Yes
Application ntp ntp 4.2.8 Yes
Application netapp cloud_backup - Yes
Application netapp clustered_data_ontap - Yes
Application netapp data_ontap - Yes
Application netapp element_software - Yes
Application netapp hci_management_node - Yes
Application netapp ontap_tools - Yes
Application netapp solidfire - Yes
Application netapp steelstore_cloud_integrated_storage - Yes
Operating System netapp hci_compute_node_firmware - Yes
Hardware netapp hci_compute_node - No
Operating System netapp h410c_firmware - Yes
Hardware netapp h410c - No
Operating System netapp h300s_firmware - Yes
Hardware netapp h300s - No
Operating System netapp h500s_firmware - Yes
Hardware netapp h500s - No
Operating System netapp h700s_firmware - Yes
Hardware netapp h700s - No
Operating System netapp h300e_firmware - Yes
Hardware netapp h300e - No
Operating System netapp h500e_firmware - Yes
Hardware netapp h500e - No
Operating System netapp h700e_firmware - Yes
Hardware netapp h700e - No
Operating System netapp h410s_firmware - Yes
Hardware netapp h410s - No
Operating System opensuse leap 15.1 Yes
Operating System opensuse leap 15.2 Yes
Operating System fujitsu m10-1_firmware < xcp2410 Yes
Hardware fujitsu m10-1 - No
Operating System fujitsu m10-4_firmware < xcp2410 Yes
Hardware fujitsu m10-4 - No
Operating System fujitsu m10-4s_firmware < xcp2410 Yes
Hardware fujitsu m10-4s - No
Operating System fujitsu m12-1_firmware < xcp2410 Yes
Hardware fujitsu m12-1 - No
Operating System fujitsu m12-2_firmware < xcp2410 Yes
Hardware fujitsu m12-2 - No
Operating System fujitsu m12-2s_firmware < xcp2410 Yes
Hardware fujitsu m12-2s - No
Operating System fujitsu m10-4_firmware < xcp3110 Yes
Hardware fujitsu m10-4 - No
Operating System fujitsu m10-4s_firmware < xcp3110 Yes
Hardware fujitsu m10-4s - No
Operating System fujitsu m12-1_firmware < xcp3110 Yes
Hardware fujitsu m12-1 - No
Operating System fujitsu m12-2_firmware < xcp3110 Yes
Hardware fujitsu m12-2 - No
Operating System fujitsu m12-2s_firmware < xcp3110 Yes
Hardware fujitsu m12-2s - No

References