CVE-2018-7184

UnknownEPSS 8.86%

Last modified

CVE-2018-7184 is a vulnerability of currently unknown severity. ntpd in ntp 4.2.8p4 before 4.2.8p11 drops bad packets before updating the "received" timestamp, which allows remote attackers to cause a denial of service (disruption) by sending a packet with a zero-origin timestamp causing the association to reset and setting the contents of the packet as the most recent timestamp. This issue is a result of an incomplete fix for CVE-2015-7704.. EPSS estimates a 8.86% chance of exploitation in the next 30 days.

Description

ntpd in ntp 4.2.8p4 before 4.2.8p11 drops bad packets before updating the "received" timestamp, which allows remote attackers to cause a denial of service (disruption) by sending a packet with a zero-origin timestamp causing the association to reset and setting the contents of the packet as the most recent timestamp. This issue is a result of an incomplete fix for CVE-2015-7704.

Metrics

EPSS Probability
8.86%

94.5th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersionsUpdate
NtpNtp4.2.8P10
SynologyRouter Manager1.1
SynologySkynasAll versions
SynologyVirtual Diskstation ManagerAll versions
SynologyDiskstation Manager5.2
SynologyDiskstation Manager6.0
SynologyDiskstation Manager6.1
SynologyVs960hd FirmwareAll versions
SlackwareSlackware Linux14.0
SlackwareSlackware Linux14.1
SlackwareSlackware Linux14.2
CanonicalUbuntu Linux14.04
CanonicalUbuntu Linux16.04
CanonicalUbuntu Linux17.10
CanonicalUbuntu Linux18.04
NetappCloud BackupAll versions
NetappSteelstore Cloud Integrated StorageAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2018-7184?
ntpd in ntp 4.2.8p4 before 4.2.8p11 drops bad packets before updating the "received" timestamp, which allows remote attackers to cause a denial of service (disruption) by sending a packet with a zero-origin timestamp causing the association to reset and setting the contents of the packet as the most recent timestamp. This issue is a result of an incomplete fix for CVE-2015-7704.
How severe is CVE-2018-7184?
Severity scoring for CVE-2018-7184 is pending analysis. The EPSS model estimates a 8.86% probability of exploitation in the next 30 days.
How do I fix CVE-2018-7184?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2018-7184?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST