CVE-2020-13817
7.4
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
Exploitability: 2.2 / Impact: 5.2
Source: NVD
Description
ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows remote attackers to cause a denial of service (daemon exit or system time change) by predicting transmit timestamps for use in spoofed packets. The victim must be relying on unauthenticated IPv4 time sources. There must be an off-path attacker who can query time from the victim's ntpd instance.
Affected (59)
Products: Ntp: Ntp · Netapp: Cloud Backup, Clustered Data Ontap, Data Ontap, Element Software, Hci Management Node, Ontap Tools, Solidfire, Steelstore Cloud Integrated Storage, Hci Compute Node Firmware, H410c Firmware, H300s Firmware, H500s Firmware, H700s Firmware, H300e Firmware, H500e Firmware, H700e Firmware, H410s Firmware · Opensuse: Leap · +1 more
Show all products
Ntp: Ntp · Netapp: Cloud Backup, Clustered Data Ontap, Data Ontap, Element Software, Hci Management Node, Ontap Tools, Solidfire, Steelstore Cloud Integrated Storage, Hci Compute Node Firmware, H410c Firmware, H300s Firmware, H500s Firmware, H700s Firmware, H300e Firmware, H500e Firmware, H700e Firmware, H410s Firmware · Opensuse: Leap · Fujitsu: M10 1 Firmware, M10 4 Firmware, M10 4s Firmware, M12 1 Firmware, M12 2 Firmware, M12 2s Firmware
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp Hci Compute Node | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp H410c | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp H300s | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp H500s | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp H700s | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp H300e | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp H500e | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp H700e | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp H410s | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp2410 |
| Running on/with | Platform Versions |
|---|---|
Fujitsu M10 1 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp2410 |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp2410 |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp2410 |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp2410 |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp2410 |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp3110 |
| Running on/with | Platform Versions |
|---|---|
Fujitsu M10 4 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp3110 |
| Running on/with | Platform Versions |
|---|---|
Fujitsu M10 4s | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp3110 |
| Running on/with | Platform Versions |
|---|---|
Fujitsu M12 1 | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp3110 |
| Running on/with | Platform Versions |
|---|---|
Fujitsu M12 2 | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Before xcp3110 |
| Running on/with | Platform Versions |
|---|---|
Fujitsu M12 2s | All versions |
References (14)
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Timeline
No history available yet.