CVE-2017-6463 is a denial-of-service vulnerability affecting NTP versions prior to 4.2.8p10 and 4.3.x before 4.3.94. An authenticated remote attacker can crash the NTP daemon by providing an invalid setting within a :config directive, specifically related to the unpeer option. This medium-severity vulnerability has a CVSS score of 6.5, indicating a network-based attack with low complexity and requiring low privileges, leading to high availability impact. There is no evidence of active exploitation, nor are public exploits available in Metasploit or ExploitDB. Despite limited community discussion, it has received some media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.2.8CPE matchmatch criteria | cpe:2.3:a:ntp:ntp:4.2.8:p9:*:*:*:*:*:* | ||
4.3.0CPE matchmatch criteria | cpe:2.3:a:ntp:ntp:4.3.0:*:*:*:*:*:*:* | ||
4.3.1CPE matchmatch criteria | cpe:2.3:a:ntp:ntp:4.3.1:*:*:*:*:*:*:* | ||
4.3.2CPE matchmatch criteria | cpe:2.3:a:ntp:ntp:4.3.2:*:*:*:*:*:*:* | ||
4.3.3CPE matchmatch criteria | cpe:2.3:a:ntp:ntp:4.3.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.