Vulnerability Details CVE-2020-11868
ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronization via a server mode packet with a spoofed source IP address, because transmissions are rescheduled even when a packet lacks a valid origin timestamp.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 68.3%
CVSS Severity
CVSS v3 Score 5.9
CVSS v2 Score 5.0
Products affected by CVE-2020-11868
-
cpe:2.3:a:netapp:data_ontap:-
-
cpe:2.3:a:netapp:hci_management_node:-
-
cpe:2.3:a:netapp:solidfire:-
-
cpe:2.3:a:netapp:vasa_provider_for_clustered_data_ontap:7.2
-
cpe:2.3:a:netapp:vasa_provider_for_clustered_data_ontap:9.6
-
cpe:2.3:a:netapp:vasa_provider_for_clustered_data_ontap:9.7
-
cpe:2.3:a:netapp:virtual_storage_console:7.2
-
cpe:2.3:a:netapp:virtual_storage_console:7.2.1
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
cpe:2.3:h:netapp:all_flash_fabric-attached_storage_8300:-
-
cpe:2.3:h:netapp:all_flash_fabric-attached_storage_8700:-
-
cpe:2.3:h:netapp:all_flash_fabric-attached_storage_a400:-
-
cpe:2.3:h:netapp:fabric-attached_storage_8300:-
-
cpe:2.3:h:netapp:fabric-attached_storage_8700:-
-
cpe:2.3:h:netapp:fabric-attached_storage_a400:-
-
cpe:2.3:h:netapp:hci_storage_node:-
-
cpe:2.3:o:debian:debian_linux:8.0
-
cpe:2.3:o:netapp:all_flash_fabric-attached_storage_8300_firmware:-
-
cpe:2.3:o:netapp:all_flash_fabric-attached_storage_8700_firmware:-
-
cpe:2.3:o:netapp:all_flash_fabric-attached_storage_a400_firmware:-
-
cpe:2.3:o:netapp:clustered_data_ontap:-
-
cpe:2.3:o:netapp:fabric-attached_storage_8300_firmware:-
-
cpe:2.3:o:netapp:fabric-attached_storage_8700_firmware:-
-
cpe:2.3:o:netapp:fabric-attached_storage_a400_firmware:-
-
cpe:2.3:o:netapp:hci_storage_node_firmware:-
-
cpe:2.3:o:opensuse:leap:15.1
-
cpe:2.3:o:opensuse:leap:15.2
-
cpe:2.3:o:redhat:enterprise_linux:7.0