VulnerabilityModified
CVE-2016-7433
NTP before 4.2.8p9 does not properly perform the initial sync calculations, which allows remote attackers to unspecified impact via unknown vectors, related to a "root distance that did not include the peer dispersion."
MEDIUM 5.3EPSS 9.84%
Does this matter?
Lower severity and a low EPSS score (9.84%). Track it; it rarely justifies an emergency change on its own.
Description
NTP before 4.2.8p9 does not properly perform the initial sync calculations, which allows remote attackers to unspecified impact via unknown vectors, related to a "root distance that did not include the peer dispersion."
- CVSS 3.0
- 5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- EPSS
- 9.84% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-682
- Affected
- ntp/ntp
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-updates/2016-12/msg00153.html
- http://nwtime.org/ntp428p9_release/Release Notes, Vendor Advisory
- http://rhn.redhat.com/errata/RHSA-2017-0252.html
- http://support.ntp.org/bin/view/Main/NtpBug3067Issue Tracking, Mitigation, Vendor Advisory
- http://support.ntp.org/bin/view/Main/SecurityNotice#Recent_VulnerabilitiesVendor Advisory
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171129-01-ntpd-en
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
- http://www.securityfocus.com/archive/1/539955/100/0/threaded
- http://www.securityfocus.com/archive/1/540254/100/0/threaded
- http://www.securityfocus.com/archive/1/archive/1/539955/100/0/threaded
- http://www.securityfocus.com/archive/1/archive/1/540254/100/0/threaded
- http://www.securityfocus.com/bid/94455
- http://www.securitytracker.com/id/1037354
- http://www.ubuntu.com/usn/USN-3349-1
- https://bto.bluecoat.com/security-advisory/sa139
- https://cert-portal.siemens.com/productcert/pdf/ssa-211752.pdf
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03706en_us
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ILMSYVQMMF37MANYEO7KBHOPSC74EKGN/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PABKEYX6ABBFJZGMXKH57X756EJUDS3C/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U5E3XBBCK5IXOLDAH2E4M3QKIYIHUMMP/
- https://security.FreeBSD.org/advisories/FreeBSD-SA-16:39.ntp.asc
- https://us-cert.cisa.gov/ics/advisories/icsa-21-159-11
- https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2017-227
- https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2017-227/
- https://www.kb.cert.org/vuls/id/633847Third Party Advisory, US Government Resource
- http://lists.opensuse.org/opensuse-updates/2016-12/msg00153.html
- http://nwtime.org/ntp428p9_release/Release Notes, Vendor Advisory
- http://rhn.redhat.com/errata/RHSA-2017-0252.html
- http://support.ntp.org/bin/view/Main/NtpBug3067Issue Tracking, Mitigation, Vendor Advisory
- http://support.ntp.org/bin/view/Main/SecurityNotice#Recent_VulnerabilitiesVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.