CVE-2016-7428 describes a denial-of-service vulnerability in ntpd versions prior to 4.2.8p9, affecting the Network Time Protocol (NTP) daemon. A remote attacker can exploit this by sending a specially crafted broadcast packet with a manipulated poll interval, causing the NTP daemon to reject subsequent broadcast mode packets. This vulnerability has a CVSS v3.0 score of 4.3 (Medium), indicating a low impact denial of service that can be triggered with low attack complexity over an adjacent network. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.2.8CPE matchmatch criteria | cpe:2.3:a:ntp:ntp:4.2.8:p6:*:*:*:*:*:* | ||
4.2.8CPE matchmatch criteria | cpe:2.3:a:ntp:ntp:4.2.8:p7:*:*:*:*:*:* | ||
4.2.8CPE matchmatch criteria | cpe:2.3:a:ntp:ntp:4.2.8:p8:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.