CVE-2018-7170: HPE Hpux-Ntp

Medium severity, CVSS 5.3. EPSS: 2.7% chance of exploitation in the next 30 days.

ntpd in ntp 4.2.x before 4.2.8p7 and 4.3.x before 4.3.92 allows authenticated users that know the private symmetric key to create arbitrarily-many ephemeral associations in order to win the clock selection of ntpd and modify a victim's clock via a Sybil attack. This issue exists because of an incomplete fix for CVE-2016-1549.

Affected products

  • HPE Hpux-Ntp: before c.4.2.8.4.0 (fixed in c.4.2.8.4.0)
  • Netapp Hci: affected versions not specified
  • Netapp Solidfire: affected versions not specified
  • Ntp Ntp: from 4.2.0, before 4.2.8 (fixed in 4.2.8); from 4.3.0, before 4.3.92 (fixed in 4.3.92); version 4.2.8 only
  • Synology Diskstation Manager: from 5.2, before 6.1.6-15266 (fixed in 6.1.6-15266)
  • Synology Router Manager: from 1.1, before 1.1.6-6931-3 (fixed in 1.1.6-6931-3)
  • Synology Skynas: before 6.1.5-15254 (fixed in 6.1.5-15254)
  • Synology Virtual Diskstation Manager: before 6.1.6-15266 (fixed in 6.1.6-15266)
  • Synology VS960HD Firmware: before 2.2.3-1505 (fixed in 2.2.3-1505)

Published 2018-03-06. Last modified 2026-06-17.