MEDIUM · 5.9

CVE-2016-9042

An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticated network packet can be used to reset the expected ...

Vulnerability Description

An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticated network packet can be used to reset the expected origin timestamp for target peers. Legitimate replies from targeted peers will fail the origin timestamp check (TEST2) causing the reply to be dropped and creating a denial of service condition.

CVSS Score

5.9

MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
NtpNtp4.2.8
FreebsdFreebsd10.0
HpeHpux-Ntp< c.4.2.8.4.0
SiemensSimatic Net Cp 443-1 Opc Ua FirmwareAll versions
SiemensSimatic Net Cp 443-1 Opc Ua-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2016-9042?

CVE-2016-9042 is a vulnerability with a CVSS score of 5.9 (MEDIUM). An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticated network packet can be used to reset the expected ...

How severe is CVE-2016-9042?

CVE-2016-9042 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2016-9042?

Check the references section above for vendor advisories and patch information. Affected products include: Ntp Ntp, Freebsd Freebsd, Hpe Hpux-Ntp, Siemens Simatic Net Cp 443-1 Opc Ua Firmware, Siemens Simatic Net Cp 443-1 Opc Ua.