Security Advisory

CVE-2018-7170

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-03-06 20:00:00
Last updated 2024-08-05 06:24:10
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

ntpd in ntp 4.2.x before 4.2.8p7 and 4.3.x before 4.3.92 allows authenticated users that know the private symmetric key to create arbitrarily-many ephemeral associations in order to win the clock selection of ntpd and modify a victim's clock via a Sybil attack. This issue exists because of an incomplete fix for CVE-2016-1549.