---
cve: "CVE-2018-8956"
severity: "LOW"
cvss: 3.1
epss: "3%"
vendor: "n/a"
kev: false
exploited: false
published: "2020-05-06 19:15:12"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-18T02:36:58+02:00"
---

# CVE-2018-8956

> 3.1 LOW

## Beschreibung

ntpd in ntp 4.2.8p10, 4.2.8p11, 4.2.8p12 and 4.2.8p13 allow remote attackers to prevent a broadcast client from synchronizing its clock with a broadcast NTP server via soofed mode 3 and mode 5 packets. The attacker must either be a part of the same broadcast network or control a slave in that broadcast network that can capture certain required packets on the attacker's behalf and send them to the attacker.

## Referenzen

- <http://www.ntp.org/>
- <https://tools.ietf.org/html/rfc5905>
- <https://nikhiltripathi.in/NTP_attack.pdf>
- <https://arxiv.org/abs/2005.01783>
- <https://security.netapp.com/advisory/ntap-20200518-0006/>
- <http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00005.html>
- <http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00044.html>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2018-8956) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
