MEDIUM

CVE-2016-9042

CVSS v3

5.9

MEDIUM

EPSS Score

4.8%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticated network packet can be used to reset the expected origin timestamp for target peers. Legitimate replies from targeted peers will fail the origin timestamp check (TEST2) causing the reply to be dropped and creating a denial of service condition.

Technical details

Published
6/4/2018

Frequently asked questions

What is CVE-2016-9042?

An exploitable denial of service vulnerability exists in the origin timestamp check functionality of ntpd 4.2.8p9. A specially crafted unauthenticated network packet can be used to reset the expected origin timestamp for target peers. Legitimate replies from targeted peers will fail the origin timestamp check (TEST2) causing the reply to be dropped and creating a denial of service condition.

Is CVE-2016-9042 actively exploited?

Active exploitation of CVE-2016-9042 has not been confirmed. The EPSS score is 4.8%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2016-9042?

CVE-2016-9042 has a CVSS v3 base score of 5.9 (MEDIUM severity).

Is CVE-2016-9042 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.