CVSS v3
5.9
MEDIUM
EPSS Score
4.8%
exploit probability
CISA KEV
No
known exploited
Exploitation
—
SSVC status
An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticated network packet can be used to reset the expected origin timestamp for target peers. Legitimate replies from targeted peers will fail the origin timestamp check (TEST2) causing the reply to be dropped and creating a denial of service condition.
An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticated network packet can be used to reset the expected origin timestamp for target peers. Legitimate replies from targeted peers will fail the origin timestamp check (TEST2) causing the reply to be dropped and creating a denial of service condition.
Active exploitation of CVE-2016-9042 has not been confirmed. The EPSS score is 4.8%, indicating the estimated probability of exploitation in the next 30 days.
CVE-2016-9042 has a CVSS v3 base score of 5.9 (MEDIUM severity).
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
Ranked by exploit probability (EPSS).