CVE-2016-7428: Medium severity NTP ntp vulnerability
Last updated 25 August 2025
Other sources
ntpd in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (reject broadcast mode packets) via the poll interval in a broadcast packet.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/ntpto a version that resolves this vulnerability.Fixed in 1:4.2.8p15+dfsg-1 - Upgrade
Upgrade
ntpdto a version that resolves this vulnerability.Fixed in 4.2.8p9
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2016-7428.
What is the severity of CVE-2016-7428?
The severity of CVE-2016-7428 is medium with a CVSS score of 4.3.
Which software versions are affected by CVE-2016-7428?
The affected software versions for CVE-2016-7428 include NTP versions before 4.2.8p9.
How can remote attackers exploit CVE-2016-7428?
Remote attackers can exploit CVE-2016-7428 to cause a denial of service by sending specific broadcast packets.
How can I mitigate CVE-2016-7428?
To mitigate CVE-2016-7428, update your NTP software to version 4.2.8p9 or later.