ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronization via a server mode packet with a spoofed source IP address, because transmissions are rescheduled even when a packet lacks a valid origin timestamp.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Debian
Subscribe
|
Debian Linux
Subscribe
|
|
Netapp
Subscribe
|
All Flash Fabric-attached Storage 8300
Subscribe
All Flash Fabric-attached Storage 8300 Firmware
Subscribe
All Flash Fabric-attached Storage 8700
Subscribe
All Flash Fabric-attached Storage 8700 Firmware
Subscribe
All Flash Fabric-attached Storage A400
Subscribe
All Flash Fabric-attached Storage A400 Firmware
Subscribe
Clustered Data Ontap
Subscribe
Data Ontap
Subscribe
Fabric-attached Storage 8300
Subscribe
Fabric-attached Storage 8300 Firmware
Subscribe
Fabric-attached Storage 8700
Subscribe
Fabric-attached Storage 8700 Firmware
Subscribe
Fabric-attached Storage A400
Subscribe
Fabric-attached Storage A400 Firmware
Subscribe
Hci Management Node
Subscribe
Hci Storage Node
Subscribe
Hci Storage Node Firmware
Subscribe
Solidfire
Subscribe
Vasa Provider For Clustered Data Ontap
Subscribe
Virtual Storage Console
Subscribe
|
|
Ntp
Subscribe
|
Ntp
Subscribe
|
|
Opensuse
Subscribe
|
Leap
Subscribe
|
|
Redhat
Subscribe
|
Enterprise Linux
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2201-1 | ntp security update |
EUVD |
EUVD-2020-4208 | ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronization via a server mode packet with a spoofed source IP address, because transmissions are rescheduled even when a packet lacks a valid origin timestamp. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 05 May 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-05-05T17:08:18.997Z
Reserved: 2020-04-17T00:00:00.000Z
Link: CVE-2020-11868
Updated: 2024-08-04T11:42:00.271Z
Status : Modified
Published: 2020-04-17T04:15:10.987
Modified: 2025-05-05T17:15:57.667
Link: CVE-2020-11868
OpenCVE Enrichment
No data.
Debian DLA
EUVD