SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2016-7433

NTP before 4.2.8p9 does not properly perform the initial sync calculations, which allows remote attackers to unspecified impact via unknown vectors, related to a "root distance that did not include the peer dispersion."

MEDIUM 5.3EPSS 9.84%

Does this matter?

Lower severity and a low EPSS score (9.84%). Track it; it rarely justifies an emergency change on its own.

Description

NTP before 4.2.8p9 does not properly perform the initial sync calculations, which allows remote attackers to unspecified impact via unknown vectors, related to a "root distance that did not include the peer dispersion."

CVSS 3.0
5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
EPSS
9.84% probability · 95th percentile
CISA KEV
Not listed
Weakness
CWE-682
Affected
ntp/ntp
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.