CVE-2009-3563 is a denial-of-service vulnerability affecting NTP daemons in NTP versions before 4.2.4p8 and 4.2.5. Attackers can exploit this by sending spoofed MODE_PRIVATE requests or responses, triggering an endless loop of error exchanges between two NTP servers, leading to high CPU and bandwidth consumption. This vulnerability has a CVSS score of 6.4, indicating a medium severity, and can be exploited remotely with low attack complexity and no authentication required, resulting in partial impact to integrity and availability. While not listed in CISA's KEV catalog, a Metasploit module exists for exploitation, and it has garnered significant community discussion and media coverage, suggesting awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.2.2p4CPE matchmatch criteria | cpe:2.3:a:ntp:ntp:*:*:*:*:*:*:*:* | ||
4.0.72CPE matchmatch criteria | cpe:2.3:a:ntp:ntp:4.0.72:*:*:*:*:*:*:* | ||
4.0.73CPE matchmatch criteria | cpe:2.3:a:ntp:ntp:4.0.73:*:*:*:*:*:*:* | ||
4.0.90CPE matchmatch criteria | cpe:2.3:a:ntp:ntp:4.0.90:*:*:*:*:*:*:* | ||
4.0.91CPE matchmatch criteria | cpe:2.3:a:ntp:ntp:4.0.91:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.