ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronization via a server mode packet with a spoofed source IP address, because transmissions are rescheduled even when a packet lacks a valid origin timestamp.

Project Subscriptions

Vendors Products
Debian Linux Subscribe
All Flash Fabric-attached Storage 8300 Subscribe
All Flash Fabric-attached Storage 8300 Firmware Subscribe
All Flash Fabric-attached Storage 8700 Subscribe
All Flash Fabric-attached Storage 8700 Firmware Subscribe
All Flash Fabric-attached Storage A400 Subscribe
All Flash Fabric-attached Storage A400 Firmware Subscribe
Clustered Data Ontap Subscribe
Data Ontap Subscribe
Fabric-attached Storage 8300 Subscribe
Fabric-attached Storage 8300 Firmware Subscribe
Fabric-attached Storage 8700 Subscribe
Fabric-attached Storage 8700 Firmware Subscribe
Fabric-attached Storage A400 Subscribe
Fabric-attached Storage A400 Firmware Subscribe
Hci Management Node Subscribe
Hci Storage Node Subscribe
Hci Storage Node Firmware Subscribe
Solidfire Subscribe
Vasa Provider For Clustered Data Ontap Subscribe
Virtual Storage Console Subscribe
Opensuse Subscribe
Enterprise Linux Subscribe
Advisories
Source ID Title
Debian DLA Debian DLA DLA-2201-1 ntp security update
EUVD EUVD EUVD-2020-4208 ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronization via a server mode packet with a spoofed source IP address, because transmissions are rescheduled even when a packet lacks a valid origin timestamp.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 05 May 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-05-05T17:08:18.997Z

Reserved: 2020-04-17T00:00:00.000Z

Link: CVE-2020-11868

cve-icon Vulnrichment

Updated: 2024-08-04T11:42:00.271Z

cve-icon NVD

Status : Modified

Published: 2020-04-17T04:15:10.987

Modified: 2025-05-05T17:15:57.667

Link: CVE-2020-11868

cve-icon Redhat

Severity : Low

Publid Date: 2020-03-03T00:00:00Z

Links: CVE-2020-11868 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses