CVE-2016-4955: Novell Suse Manager
Medium severity, CVSS 5.9. EPSS: 8.8% chance of exploitation in the next 30 days.
ntpd in NTP 4.x before 4.2.8p8, when autokey is enabled, allows remote attackers to cause a denial of service (peer-variable clearing and association outage) by sending (1) a spoofed crypto-NAK packet or (2) a packet with an incorrect MAC value at a certain time.
Affected products
- Novell Suse Manager: version 2.1 only
- Ntp Ntp: from 4.2.0, before 4.2.8 (fixed in 4.2.8); from 4.3.0, before 4.3.93 (fixed in 4.3.93); version 4.2.8 only
- Opensuse Leap: version 42.1 only
- Opensuse Opensuse: version 13.2 only
- Oracle Solaris: version 10 only; version 11.3 only
- Siemens SIMATIC Net CP 443-1 Opc Ua Firmware: any version
- Suse Linux Enterprise Desktop: version 12 only
- Suse Linux Enterprise Server: version 11 only; version 12 only
- Suse Manager Proxy: version 2.1 only
- Suse Openstack Cloud: version 5 only
Published 2016-07-05. Last modified 2026-06-17.