SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2016-9042

An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9.

MEDIUM 5.9EPSS 3.91%

Does this matter?

Lower severity and a low EPSS score (3.91%). Track it; it rarely justifies an emergency change on its own.

Description

An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticated network packet can be used to reset the expected origin timestamp for target peers. Legitimate replies from targeted peers will fail the origin timestamp check (TEST2) causing the reply to be dropped and creating a denial of service condition.

CVSS 3.1
5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
3.91% probability · 90th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
ntp/ntp · freebsd/freebsd · hpe/hpux-ntp · siemens/simatic net cp 443-1 opc ua firmware
Source
talos-cna@cisco.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.