CVE-2016-4955 describes a denial-of-service vulnerability in NTP 4.x before version 4.2.8p8, specifically when the autokey feature is enabled. This flaw allows remote attackers to disrupt NTP services by sending spoofed crypto-NAK packets or packets with incorrect MAC values, affecting products from vendors like Novell, NTP, and Oracle. The vulnerability has a CVSS v3.1 score of 5.9 (Medium), indicating a high availability impact with high attack complexity, as it requires specific timing for successful exploitation. Attackers can cause peer-variable clearing and association outages, leading to service disruption. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has received some media coverage and community discussion, suggesting awareness within the security community. It is not listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.2.0, < 4.2.8CPE matchmatch criteria | cpe:2.3:a:ntp:ntp:*:*:*:*:*:*:*:* | ||
>= 4.3.0, < 4.3.93CPE matchmatch criteria | cpe:2.3:a:ntp:ntp:*:*:*:*:*:*:*:* | ||
4.2.8CPE matchmatch criteria | cpe:2.3:a:ntp:ntp:4.2.8:-:*:*:*:*:*:* | ||
4.2.8CPE matchmatch criteria | cpe:2.3:a:ntp:ntp:4.2.8:p1:*:*:*:*:*:* | ||
4.2.8CPE matchmatch criteria | cpe:2.3:a:ntp:ntp:4.2.8:p1-beta1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.