CVE-2009-3563
Ntp < 4.2.2p4 - Denial of Service
Title source: ruleDescription
ntp_request.c in ntpd in NTP before 4.2.4p8, and 4.2.5, allows remote attackers to cause a denial of service (CPU and bandwidth consumption) by using MODE_PRIVATE to send a spoofed (1) request or (2) response packet that triggers a continuous exchange of MODE_PRIVATE error responses between two NTP daemons.
Exploits (1)
metasploit
WORKING POC
by todb · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/dos/ntp/ntpd_reserved_dos.rb
References (43)
... and 23 more
Scores
EPSS
0.7963
EPSS Percentile
99.1%
Details
Status
published
Products (21)
ntp/ntp
4.0.72
ntp/ntp
4.0.73
ntp/ntp
4.0.90
ntp/ntp
4.0.91
ntp/ntp
4.0.92
ntp/ntp
4.0.93
ntp/ntp
4.0.94
ntp/ntp
4.0.95
ntp/ntp
4.0.96
ntp/ntp
4.0.97
... and 11 more
Published
Dec 09, 2009
Tracked Since
Feb 18, 2026