The rate limiting feature in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to have unspecified impact via a large number of crafted requests.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCitrix Xenserver
APPCitrix6.0.26.2.06.57.0Netapp Clustered Data Ontap
OSNetappall versionsNetapp Data Ontap
OSNetappall versionsNetapp Oncommand Performance Manager
APPNetappall versionsNetapp Oncommand Unified Manager
APPNetappall versionsNtp
APPNtp4.2.84.2.0 – 4.2.8 (excl.)4.3.0 – 4.3.77 (excl.)Siemens Tim 4r Ie
HWSiemensall versionsSiemens Tim 4r Ie Dnp3
HWSiemensall versionsSiemens Tim 4r Ie Dnp3 Firmware
OSSiemensall versionsSiemens Tim 4r Ie Firmware
OSSiemensall versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References
Related vulnerabilities
CVE-2021-40438CRITICAL9.0⚠ KEVPL ✓same product
SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego
CVE-2016-3427CRITICAL9.8⚠ KEVPL ✓same product
Krytyczna podatność RCE w Oracle Java SE i JRockit — komponent JMX
CVE-2024-38476CRITICAL9.8PL ✓same product
Apache HTTP Server – ujawnienie danych, SSRF lub wykonanie skryptu przez nagłówki backendu
CVE-2024-38474CRITICAL9.8PL ✓same product
Apache HTTP Server mod_rewrite — wykonanie skryptów lub ujawnienie kodu źródłowego
CVE-2023-23914CRITICAL9.1PL ✓same product
curl: pominięcie ochrony HSTS przy seryjnym pobieraniu wielu URL-i