CVE-2009-3563
MEDIUM 6.4EPSS 32.1%
ntp_request.c in ntpd in NTP before 4.2.4p8, and 4.2.5, allows remote attackers to cause a denial of service (CPU and bandwidth consumption) by using MODE_PRIVATE to send a spoofed (1) request or (2) response packet that triggers a continuous exchange of MODE_PRIVATE error responses between two NTP daemons.
- CVSS v2.0
- 6.4 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:P - EPSS
- 32.06% chance of exploitation in the next 30 days, 98th percentile
- Published
- 2009-12-09
- Updated
- 2024-08-07