CVE-2016-4957 is a high-severity denial-of-service vulnerability affecting NTP before version 4.2.8p8, including products from Novell, OpenSUSE, Oracle, and SUSE. This flaw, an incorrect fix for CVE-2016-1547, allows remote unauthenticated attackers to crash the NTP daemon by sending a specially crafted crypto-NAK packet. With a CVSS score of 7.5 (HIGH), it requires no user interaction and has a high impact on availability. While there is no evidence of active exploitation, no public exploit code, and limited community discussion, its high EPSS and FAUCET Risk Score indicate a significant potential risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.2.8CPE matchmatch criteria | cpe:2.3:a:ntp:ntp:4.2.8:p7:*:*:*:*:*:* | ||
4.3.92CPE matchmatch criteria | cpe:2.3:a:ntp:ntp:4.3.92:*:*:*:*:*:*:* | ||
10CPE matchmatch criteria | cpe:2.3:o:oracle:solaris:10:*:*:*:*:*:*:* | ||
11.3CPE matchmatch criteria | cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:* | ||
2.1CPE matchmatch criteria | cpe:2.3:a:suse:manager_proxy:2.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.