CVE Feed

    Dashboard / CVE / CVE-2020-13817

    CVE-2020-13817

    ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows remote attackers to cause a denial of service (daemon exit or system time change) by predicting transmit timestamps for use in spoofed packets. The victim must be relying on unauthenticated IPv4 time sources. There must be an off-path attacker who can query time from the victim's ntpd instance.

    Published:Mar 3, 2020
    Last Modified:May 5, 2025
    EPS:Jun 4, 2020
    EPSS Score:0.00375
    CVSS Score:7.4

    Affected Products

    Vendor
    Fujitsu
    Product
    M10-1
    Vendor
    Fujitsu
    Product
    M10-1 Firmware
    Vendor
    Fujitsu
    Product
    M10-4
    Vendor
    Fujitsu
    Product
    M10-4 Firmware
    Vendor
    Fujitsu
    Product
    M10-4s
    Vendor
    Fujitsu
    Product
    M10-4s Firmware
    Vendor
    Fujitsu
    Product
    M12-1
    Vendor
    Fujitsu
    Product
    M12-1 Firmware
    Vendor
    Fujitsu
    Product
    M12-2
    Vendor
    Fujitsu
    Product
    M12-2 Firmware
    Vendor
    Fujitsu
    Product
    M12-2s
    Vendor
    Fujitsu
    Product
    M12-2s Firmware
    Vendor
    Netapp
    Product
    Cloud Backup
    Vendor
    Netapp
    Product
    Clustered Data Ontap
    Vendor
    Netapp
    Product
    Data Ontap
    Vendor
    Netapp
    Product
    Element Software
    Vendor
    Netapp
    Product
    H300e
    Vendor
    Netapp
    Product
    H300e Firmware
    Vendor
    Netapp
    Product
    H300s
    Vendor
    Netapp
    Product
    H300s Firmware
    Vendor
    Netapp
    Product
    H410c
    Vendor
    Netapp
    Product
    H410c Firmware
    Vendor
    Netapp
    Product
    H410s
    Vendor
    Netapp
    Product
    H410s Firmware
    Vendor
    Netapp
    Product
    H500e
    Vendor
    Netapp
    Product
    H500e Firmware
    Vendor
    Netapp
    Product
    H500s
    Vendor
    Netapp
    Product
    H500s Firmware
    Vendor
    Netapp
    Product
    H700e
    Vendor
    Netapp
    Product
    H700e Firmware
    Vendor
    Netapp
    Product
    H700s
    Vendor
    Netapp
    Product
    H700s Firmware
    Vendor
    Netapp
    Product
    Hci Compute Node
    Vendor
    Netapp
    Product
    Hci Compute Node Firmware
    Vendor
    Netapp
    Product
    Hci Management Node
    Vendor
    Netapp
    Product
    Ontap Tools
    Vendor
    Netapp
    Product
    Solidfire
    Vendor
    Netapp
    Product
    Steelstore Cloud Integrated Storage
    Vendor
    Ntp
    Product
    Ntp
    Vendor
    Opensuse
    Product
    Leap
    Vendor
    Redhat
    Product
    Enterprise Linux

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High