Openntpd is a lightweight network time protocol implementation focused on accurate system timekeeping across Unix-like systems, with a narrow product scope centered on the openntpd daemon itself. Observed vulnerabilities in this vendor reflect the parsing and state-management demands of protocol implementations, with weaknesses appearing in areas relevant to input handling and protocol compliance; current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openntpd over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-5117MEDIUM OpenNTPD before 6.0p1 does not validate the CN for HTTPS constraint requests, which allows remote attackers to bypass the man-in-the-middle mitigations via a crafted timestamp cons | Jan 31, 2017 | 5.9 | 16 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openntpd.
Media articles that mention a CVE ID that affects a product developed by Openntpd — matched by CVE ID, not by vendor name.