cisco-sa-CVE-2013-5211
Network Time Foundation ntpd Service Network Traffic Amplification Issue
Low · Updated · Cisco
13 products with CSAF evidence
A vulnerability in the Network Time Protocol (NTP) package of several Cisco products could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.The vulnerability is due to processing MODE_PRIVATE (Mode 7) NTP control messages, which have a large amplification vector. An attacker could exploit this vulnerability by sending Mode 7 control requests to NTP servers and observing responses amplified up to 5,500 times in size. An exploit could allow the attacker to cause a DoS condition in which the affected NTP server is forced to process and respond with large response data.