PoC Index

CVE-2009-3563

MEDIUM 6.4EPSS 32.1%

ntp_request.c in ntpd in NTP before 4.2.4p8, and 4.2.5, allows remote attackers to cause a denial of service (CPU and bandwidth consumption) by using MODE_PRIVATE to send a spoofed (1) request or (2) response packet that triggers a continuous exchange of MODE_PRIVATE error responses between two NTP daemons.

CVSS v2.0
6.4 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
EPSS
32.06% chance of exploitation in the next 30 days, 98th percentile
Published
2009-12-09
Updated
2024-08-07

Metasploit modules (1)

References

Related