CVE-2018-7170: HPE Hpux-Ntp
Medium severity, CVSS 5.3. EPSS: 2.7% chance of exploitation in the next 30 days.
ntpd in ntp 4.2.x before 4.2.8p7 and 4.3.x before 4.3.92 allows authenticated users that know the private symmetric key to create arbitrarily-many ephemeral associations in order to win the clock selection of ntpd and modify a victim's clock via a Sybil attack. This issue exists because of an incomplete fix for CVE-2016-1549.
Affected products
- HPE Hpux-Ntp: before c.4.2.8.4.0 (fixed in c.4.2.8.4.0)
- Netapp Hci: affected versions not specified
- Netapp Solidfire: affected versions not specified
- Ntp Ntp: from 4.2.0, before 4.2.8 (fixed in 4.2.8); from 4.3.0, before 4.3.92 (fixed in 4.3.92); version 4.2.8 only
- Synology Diskstation Manager: from 5.2, before 6.1.6-15266 (fixed in 6.1.6-15266)
- Synology Router Manager: from 1.1, before 1.1.6-6931-3 (fixed in 1.1.6-6931-3)
- Synology Skynas: before 6.1.5-15254 (fixed in 6.1.5-15254)
- Synology Virtual Diskstation Manager: before 6.1.6-15266 (fixed in 6.1.6-15266)
- Synology VS960HD Firmware: before 2.2.3-1505 (fixed in 2.2.3-1505)
Published 2018-03-06. Last modified 2026-06-17.