← Vulnerability feed

Vulnerability record · CVE-2019-6445 · published 16 January 2019

CVE-2019-6445: Ntpsec null pointer dereference vulnerability

Ntpsec · Ntpsec

An issue was discovered in NTPsec before 1.1.3. An authenticated attacker can cause a NULL pointer dereference and ntpd crash in ntp_control.c, related to ctl_getitem.

6.5 CVSS 3.0 Medium EPSS 14% · top 3.6% CWE-476 · NULL pointer dereference
6.5CVSS 3.0 base score, v2 4.0
14%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in NTPsec before 1.1.3. An authenticated attacker can cause a NULL pointer dereference and ntpd crash in ntp_control.c, related to ctl_getitem.

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://dumpco.re/blog/ntpsec-bugs ExploitThird Party Advisory
https://dumpco.re/bugs/ntpsec-authed-npe ExploitThird Party Advisory
https://github.com/ntpsec/ntpsec/blob/NTPsec_1_1_3/NEWS Release NotesThird Party Advisory
https://www.exploit-db.com/exploits/46177/ ExploitThird Party AdvisoryVDB Entry
https://dumpco.re/blog/ntpsec-bugs ExploitThird Party Advisory
https://dumpco.re/bugs/ntpsec-authed-npe ExploitThird Party Advisory
https://github.com/ntpsec/ntpsec/blob/NTPsec_1_1_3/NEWS Release NotesThird Party Advisory
https://www.exploit-db.com/exploits/46177/ ExploitThird Party AdvisoryVDB Entry

Track CVE-2019-6445 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2019-6443NTPsec ntpd stack buffer over-read via ctl_getitem in read_sysvarsNTPsec before 1.1.3 contains a bug in ctl_getitem that causes a stack-based buffer over-read in read_sysvars in ntp_control.c within ntpd. The flaw i…EPSS 67%analysed9.1CVE-2019-6444NTPsec ntpd control packet stack buffer over-readNTPsec before 1.1.3 has a stack-based buffer over-read in process_control() in ntp_control.c, where attacker-controlled data is dereferenced by ntohl…EPSS 46%analysed7.5CVE-2023-4012Ntpsec vulnerabilityntpd will crash if the server is not NTS-enabled (no certificate) and it receives an NTS-enabled client request (mode 3).EPSS 0.45%7.4CVE-2021-22212Ntpsec broken cryptographic algorithm vulnerabilityntpkeygen can generate keys that ntpd fails to parse. NTPsec 1.2.0 allows ntpkeygen to generate keys with '#' characters. ntpd then either pads, shor…EPSS 0.52%6.5CVE-2019-6442Ntpsec out-of-bounds write vulnerabilityAn issue was discovered in NTPsec before 1.1.3. An authenticated attacker can write one byte out of bounds in ntpd via a malformed config request, re…EPSS 14%3.7CVE-2016-1551Ntp vulnerabilityntpd in NTP 4.2.8p3 and NTPsec a5fb34b9cc89b92a8fef2f459004865c93bb7f92 relies on the underlying operating system to protect it from requests that im…EPSS 2.2%6.2CVE-2026-21525Windows Remote Access Connection Manager null pointer dereference DoSWindows Remote Access Connection Manager contains a null pointer dereference (CWE-476) that lets an unauthorized attacker deny service locally. The f…KEVEPSS 4.8%analysed

Source: NIST National Vulnerability Database (record CVE-2019-6445), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.