← Back

CVE-2020-11868

nvd nist
Published: Apr 17, 2020Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronization via a server mode packet with a spoofed source IP address, because transmissions are rescheduled even when a packet lacks a valid origin timestamp.

Affected (47)

Show all products
1 product
Ntp
1 product
Enterprise Linux
13 products
Clustered Data Ontap
Data Ontap
Hci Management Node
Solidfire
Virtual Storage Console
Hci Storage Node Firmware
1 product
Debian Linux
1 product
Leap
Configuration A
29 vulnerable
Vulnerable SoftwareAffected Versions
Ntp
Up to 4.2.7
From 4.3.98 to 4.3.100
Version 4.2.8
Version 4.2.8 p1-beta1
Version 4.2.8 p1-beta2
Version 4.2.8 p1-beta3
Version 4.2.8 p1-beta4
Version 4.2.8 p1-beta5
Version 4.2.8 p1-rc1
Version 4.2.8 p1-rc2
Version 4.2.8 p10
Version 4.2.8 p11
Version 4.2.8 p12
Version 4.2.8 p13
Version 4.2.8 p1
Version 4.2.8 p2-rc1
Version 4.2.8 p2-rc2
Version 4.2.8 p2-rc3
Version 4.2.8 p2
Version 4.2.8 p3-rc1
Version 4.2.8 p3-rc2
Version 4.2.8 p3-rc3
Version 4.2.8 p3
Version 4.2.8 p4
Version 4.2.8 p5
Version 4.2.8 p6
Version 4.2.8 p7
Version 4.2.8 p8
Version 4.2.8 p9
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 7.0
Configuration C
7 vulnerable
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
Hci Storage Node
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
Fabric Attached Storage 8300
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
Fabric Attached Storage 8700
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
Fabric Attached Storage A400
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
All Flash Fabric Attached Storage 8300
All versions
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
All Flash Fabric Attached Storage 8700
All versions
Configuration J
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
All Flash Fabric Attached Storage A400
All versions
Configuration K
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 8.0
Configuration L
2 vulnerable
Vulnerable SoftwareAffected Versions
Opensuse
Version 15.1
Version 15.2

References (16)

Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
Issue TrackingThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.