Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The config_auth function in ntpd in NTP before 4.2.7p11, when an auth key is not configured, improperly generates a key, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
NTP‘config_auth’函数安全漏洞
Vulnerability Description
NTP(Network Time Protocol,网络时间协议)是一款通过网络同步计算机时钟的协议。 NTP 4.2.7p11之前版本的ntpd中的‘config_auth’函数中存在安全漏洞,该漏洞源于程序未配置授权密钥时,错误的生成密钥。远程攻击者可通过实施暴力破解攻击者利用该漏洞绕过密码保护机制。
CVSS Information
N/A
Vulnerability Type
N/A