← All CVEs

CVE-2014-9296

medium · 5

The receive function in ntp_proto.c in ntpd in NTP before 4.2.8 continues to execute after detecting a certain authentication error, which might allow remote attackers to trigger an unintended association change via crafted packets.

5
CVSS
16.2%
EPSS (exploit prob.)
97th
EPSS percentile
2014-12-20
Published

AV:N/AC:L/Au:N/C:N/I:N/A:P

Weaknesses

CWE-17

Affected products

VendorProductAffected versions
ntpntp<= 4.2.7

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2014-9296