CVE-2020-13817
7.4
HIGH
CVSS 3.1
EPSS 4.1%
描述
ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows remote attackers to cause a denial of service (daemon exit or system time change) by predicting transmit timestamps for use in spoofed packets. The victim must be relying on unauthenticated IPv4 time sources. There must be an off-path attacker who can query time from the victim's ntpd instance.
如何修補 CVE-2020-13817
要修補 CVE-2020-13817,請將受影響套件升級到下列已修補版本。
- Debian/ntp—升級至 1:4.2.8p14+dfsg-1 或更新版本
CVE-2020-13817 正在被利用嗎?
低 — EPSS 為 4.1%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 1:4.2.8p14+dfsg-1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.4 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H |