CVE-2018-8956: Ntp
Medium severity, CVSS 5.3. EPSS: 3.1% chance of exploitation in the next 30 days.
ntpd in ntp 4.2.8p10, 4.2.8p11, 4.2.8p12 and 4.2.8p13 allow remote attackers to prevent a broadcast client from synchronizing its clock with a broadcast NTP server via soofed mode 3 and mode 5 packets. The attacker must either be a part of the same broadcast network or control a slave in that broadcast network that can capture certain required packets on the attacker's behalf and send them to the attacker.
Affected products
- Ntp Ntp: version 4.2.8 only
Published 2020-05-06. Last modified 2026-06-17.