← Vulnerability feed

Vulnerability record · CVE-2020-13817 · published 4 June 2020

CVE-2020-13817: Ntp vulnerability

Ntp · Ntp

ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows remote attackers to cause a denial of service (daemon exit or system time change) by predicting transmit timestamps for use in spoofed packets. The victim must be relying on unauthenticated IPv4 time sources. There must be an off-path attacker who can query time from the victim's ntpd instance.

7.4 CVSS 3.1 High EPSS 3.3% · top 12.1% CWE-330 · CWE-330
7.4CVSS 3.1 base score, v2 5.8
3.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
25Affected product versions listed by NVD
14References
17 Jun 2026Last modified by NVD

Description

ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows remote attackers to cause a denial of service (daemon exit or system time change) by predicting transmit timestamps for use in spoofed packets. The victim must be relying on unauthenticated IPv4 time sources. There must be an off-path attacker who can query time from the victim's ntpd instance.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H

Affected products

25 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-13817 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-1000007Haxx curl vulnerabilitylibcurl 7.1 through 7.57.0 might accidentally leak authentication data to third parties. When asked to send custom headers in its HTTP requests, libc…EPSS 8.0%7.8CVE-2020-8177Haxx curl injection vulnerabilitycurl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a local file wh…EPSS 1.3%7.5CVE-2021-23840OpenSSL EVP cipher update integer overflow causes negative output lengthCalls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate can overflow the output length argument when the input length approaches the platf…EPSS 51%analysed7.5CVE-2021-3326Gnu glibc vulnerabilityThe iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid input sequences in the ISO-2022-JP-3 encoding,…EPSS 3.1%7.5CVE-2020-8285Haxx libcurl out-of-bounds write vulnerabilitycurl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.EPSS 9.8%7.5CVE-2016-8610Openssl uncontrolled resource consumption vulnerabilityA denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALE…EPSS 40%6.8CVE-2019-6109Openbsd openssh vulnerabilityAn issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker)…EPSS 3.8%5.9CVE-2019-6111OpenSSH scp client path traversal allows arbitrary file overwriteThe scp client in OpenSSH 7.9 inherits its design from 1983 rcp, where the server decides which files and directories are sent. The client only perfo…EPSS 58%analysed

Source: NIST National Vulnerability Database (record CVE-2020-13817), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.