CVE-2018-7185
The protocol engine in ntp 4.2.6 before 4.2.8p11 allows a remote attackers to cause a denial of service (disruption) by continually sending a packet with a zero-origin timestamp and source IP address of the "other side" of an interleaved association…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (9.00%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The protocol engine in ntp 4.2.6 before 4.2.8p11 allows a remote attackers to cause a denial of service (disruption) by continually sending a packet with a zero-origin timestamp and source IP address of the "other side" of an interleaved association causing the victim ntpd to reset its association.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 9.00% probability · 95th percentile
- CISA KEV
- Not listed
- Affected
- ntp/ntp · synology/router manager · synology/skynas · synology/virtual diskstation manager · synology/diskstation manager · synology/vs960hd firmware · canonical/ubuntu linux · netapp/hci · netapp/solidfire · hpe/hpux-ntp · oracle/fujitsu m10-1 firmware · oracle/fujitsu m10-4 firmware · oracle/fujitsu m10-4s firmware · oracle/fujitsu m12-1 firmware · oracle/fujitsu m12-2 firmware · oracle/fujitsu m12-2s firmware
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/146631/Slackware-Security-Advisory-ntp-Updates.htmlThird Party Advisory, VDB Entry
- http://support.ntp.org/bin/view/Main/NtpBug3454Mitigation, Vendor Advisory
- http://www.securityfocus.com/archive/1/541824/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/103339Third Party Advisory, VDB Entry
- https://security.FreeBSD.org/advisories/FreeBSD-SA-18:02.ntp.ascThird Party Advisory
- https://security.gentoo.org/glsa/201805-12Third Party Advisory
- https://security.netapp.com/advisory/ntap-20180626-0001/Third Party Advisory
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03962en_usThird Party Advisory
- https://usn.ubuntu.com/3707-1/Third Party Advisory
- https://usn.ubuntu.com/3707-2/Third Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlThird Party Advisory
- https://www.synology.com/support/security/Synology_SA_18_13Third Party Advisory
- http://packetstormsecurity.com/files/146631/Slackware-Security-Advisory-ntp-Updates.htmlThird Party Advisory, VDB Entry
- http://support.ntp.org/bin/view/Main/NtpBug3454Mitigation, Vendor Advisory
- http://www.securityfocus.com/archive/1/541824/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/103339Third Party Advisory, VDB Entry
- https://security.FreeBSD.org/advisories/FreeBSD-SA-18:02.ntp.ascThird Party Advisory
- https://security.gentoo.org/glsa/201805-12Third Party Advisory
- https://security.netapp.com/advisory/ntap-20180626-0001/Third Party Advisory
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03962en_usThird Party Advisory
- https://usn.ubuntu.com/3707-1/Third Party Advisory
- https://usn.ubuntu.com/3707-2/Third Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlThird Party Advisory
- https://www.synology.com/support/security/Synology_SA_18_13Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.