Description
NTP before 4.2.8p9 does not properly perform the initial sync calculations, which allows remote attackers to unspecified impact via unknown vectors, related to a "root distance that did not include the peer dispersion."
References (25)
... and 5 more
Scores
CVSS v3
5.3
EPSS
0.0685
EPSS Percentile
91.4%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Details
CWE
CWE-682
Status
published
Products (1)
ntp/ntp
< 4.2.8
Published
Jan 13, 2017
Tracked Since
Feb 18, 2026