MEDIUM · 4.4

CVE-2020-15025

ntpd in ntp 4.2.8 before 4.2.8p15 and 4.3.x before 4.3.101 allows remote attackers to cause a denial of service (memory consumption) by sending packets, because memory is not freed in situations where...

Vulnerability Description

ntpd in ntp 4.2.8 before 4.2.8p15 and 4.3.x before 4.3.101 allows remote attackers to cause a denial of service (memory consumption) by sending packets, because memory is not freed in situations where a CMAC key is used and associated with a CMAC algorithm in the ntp.keys file.

CVSS Score

4.4

MEDIUM

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
NtpNtp>= 4.3.97, < 4.3.101
OpensuseLeap15.1
NetappCloud Backup-
NetappSteelstore Cloud Integrated Storage-
Netapp8300 Firmware-
Netapp8300-
Netapp8700 Firmware-
Netapp8700-
NetappA400 Firmware-
NetappA400-
NetappH410C Firmware-
NetappH410C-
NetappH300S Firmware-
NetappH300S-
NetappH500S Firmware-
NetappH500S-
NetappH700S Firmware-
NetappH700S-
NetappH300E Firmware-
NetappH300E-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-15025?

CVE-2020-15025 is a vulnerability with a CVSS score of 4.4 (MEDIUM). ntpd in ntp 4.2.8 before 4.2.8p15 and 4.3.x before 4.3.101 allows remote attackers to cause a denial of service (memory consumption) by sending packets, because memory is not freed in situations where...

How severe is CVE-2020-15025?

CVE-2020-15025 has been rated MEDIUM with a CVSS base score of 4.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-15025?

Check the references section above for vendor advisories and patch information. Affected products include: Ntp Ntp, Opensuse Leap, Netapp Cloud Backup, Netapp Steelstore Cloud Integrated Storage, Netapp 8300 Firmware.