CVE-2016-4953
HIGHNtp < 4.2.8 - Authentication Bypass
Title source: ruleDescription
ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (ephemeral-association demobilization) by sending a spoofed crypto-NAK packet with incorrect authentication data at a certain time.
References (32)
... and 12 more
Scores
CVSS v3
7.5
EPSS
0.1437
EPSS Percentile
94.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Classification
CWE
CWE-287
Status
draft
Affected Products (37)
ntp/ntp
< 4.2.8
ntp/ntp
ntp/ntp
ntp/ntp
ntp/ntp
ntp/ntp
ntp/ntp
ntp/ntp
ntp/ntp
ntp/ntp
ntp/ntp
ntp/ntp
ntp/ntp
ntp/ntp
ntp/ntp
... and 22 more
Timeline
Published
Jul 05, 2016
Tracked Since
Feb 18, 2026