HIGH · 7.5

CVE-2018-7185

The protocol engine in ntp 4.2.6 before 4.2.8p11 allows a remote attackers to cause a denial of service (disruption) by continually sending a packet with a zero-origin timestamp and source IP address ...

Vulnerability Description

The protocol engine in ntp 4.2.6 before 4.2.8p11 allows a remote attackers to cause a denial of service (disruption) by continually sending a packet with a zero-origin timestamp and source IP address of the "other side" of an interleaved association causing the victim ntpd to reset its association.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
NtpNtp>= 4.2.6, < 4.2.8
SynologyRouter Manager>= 1.1, < 1.1.6-6931-3
SynologySkynas< 6.1.5-15254
SynologyVirtual Diskstation Manager< 6.1.6-15266
SynologyDiskstation Manager>= 5.2, < 6.1.6-15266
SynologyVs960Hd Firmware< 2.2.3-1505
SynologyVs960Hd-
CanonicalUbuntu Linux12.04
NetappHci-
NetappSolidfire-
HpeHpux-Ntp< c.4.2.8.4.0
OracleFujitsu M10-1 Firmware< xcp2361
OracleFujitsu M10-1-
OracleFujitsu M10-4 Firmware< xcp2361
OracleFujitsu M10-4-
OracleFujitsu M10-4S Firmware< xcp2361
OracleFujitsu M10-4S-
OracleFujitsu M12-1 Firmware< xcp2361
OracleFujitsu M12-1-
OracleFujitsu M12-2 Firmware< xcp2361

References

FAQ

What is CVE-2018-7185?

CVE-2018-7185 is a vulnerability with a CVSS score of 7.5 (HIGH). The protocol engine in ntp 4.2.6 before 4.2.8p11 allows a remote attackers to cause a denial of service (disruption) by continually sending a packet with a zero-origin timestamp and source IP address ...

How severe is CVE-2018-7185?

CVE-2018-7185 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-7185?

Check the references section above for vendor advisories and patch information. Affected products include: Ntp Ntp, Synology Router Manager, Synology Skynas, Synology Virtual Diskstation Manager, Synology Diskstation Manager.