CVE-2019-11331: High severity ntp vulnerability
Published Apr 18, 2019
·Updated
Network Time Protocol (NTP), as specified in RFC 5905, uses port 123 even for modes where a fixed port number is not required, which makes it easier for remote attackers to conduct off-path attacks.
Affected Software
1 affected component
NTP ntp
Event History
Apr 18, 2019
CVE Published
via MITRE·09:58 PM
Data Sourced
via MITRE·09:58 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this NTP vulnerability?
The vulnerability ID for this NTP vulnerability is CVE-2019-11331.
2
What is the severity rating of CVE-2019-11331?
CVE-2019-11331 has a severity rating of 8.1 out of 10, which is considered high.
3
How does CVE-2019-11331 affect NTP software?
CVE-2019-11331 affects NTP software that uses port 123 even for modes where a fixed port number is not required.
4
What are the potential risks associated with CVE-2019-11331?
CVE-2019-11331 makes it easier for remote attackers to conduct off-path attacks, posing a significant security risk.
5
Are there any recommended fixes for CVE-2019-11331?
Yes, it is recommended to apply the necessary security patches or updates provided by the NTP software vendor to mitigate the vulnerability.