CVE-2009-3563

Ntp < 4.2.2p4 - Denial of Service

Title source: rule

Description

ntp_request.c in ntpd in NTP before 4.2.4p8, and 4.2.5, allows remote attackers to cause a denial of service (CPU and bandwidth consumption) by using MODE_PRIVATE to send a spoofed (1) request or (2) response packet that triggers a continuous exchange of MODE_PRIVATE error responses between two NTP daemons.

Exploits (1)

metasploit WORKING POC
by todb · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/dos/ntp/ntpd_reserved_dos.rb

References (43)

... and 23 more

Scores

EPSS 0.7963
EPSS Percentile 99.1%

Details

Status published
Products (21)
ntp/ntp 4.0.72
ntp/ntp 4.0.73
ntp/ntp 4.0.90
ntp/ntp 4.0.91
ntp/ntp 4.0.92
ntp/ntp 4.0.93
ntp/ntp 4.0.94
ntp/ntp 4.0.95
ntp/ntp 4.0.96
ntp/ntp 4.0.97
... and 11 more
Published Dec 09, 2009
Tracked Since Feb 18, 2026