CVE-2020-11868: High severity ibm data risk manager vulnerability
A vulnerability was found in NTP. A security issue which enables an off-path attacker to prevent ntpd from synchronizing with NTP servers not using authentication. A server mode packet with spoofed source address sent to the client ntpd causes the next transmission to be rescheduled, even if the packet doesn't have a valid origin timestamp. If the packet is sent to the client frequently enough, it will stop polling the server and not be able to synchronize with it.
Other sources
NTP is vulnerable to a denial of service, caused by a flaw in ntpd. By sending a server mode packet with a spoofed source IP address, a remote attacker could exploit this vulnerability to block unauthenticated synchronization resulting in a denial of service condition.
— IBM
ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronization via a server mode packet with a spoofed source IP address, because transmissions are rescheduled even when a packet lacks a valid origin timestamp.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-11868?
CVE-2020-11868 is a vulnerability in ntpd that allows an off-path attacker to block unauthenticated synchronization.
Which versions of ntp are affected by CVE-2020-11868?
ntpd versions before 4.2.8p14 and 4.3.x before 4.3.100 are affected.
How does CVE-2020-11868 allow an attacker to block unauthenticated synchronization?
The attacker can use a server mode packet with a spoofed source IP address, which causes transmissions to be rescheduled even without a valid origin timestamp.
What is the severity of CVE-2020-11868?
CVE-2020-11868 has a severity score of 7.5 (high).
Where can I find more information about CVE-2020-11868?
More information about CVE-2020-11868 can be found in the references: [Bugzilla Red Hat](https://bugzilla.redhat.com/show_bug.cgi?id=1716661), [NTP Bug 3592](http://support.ntp.org/bin/view/Main/NtpBug3592), [Bugzilla Red Hat](https://bugzilla.redhat.com/show_bug.cgi?id=1824831).