CVE-2023-4012: Incomplete Internal State Distinction in ntpsec
Published Aug 7, 2023
·Updated
ntpd will crash if the server is not NTS-enabled (no certificate) and it receives an NTS-enabled client request (mode 3).
Affected Software
1 affected component
NTPsec NTPsec=1.2.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
NTPsecto a version that resolves this vulnerability.Fixed in 1.2.2a - Upgrade
Upgrade
NTPsecto a version that resolves this vulnerability.Fixed in 1.2.3
Event History
Aug 7, 2023
CVE Published
via MITRE·05:30 PM
Data Sourced
via MITRE·05:30 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-4012?
CVE-2023-4012 has been rated as a medium severity vulnerability due to potential system crashes.
2
How do I fix CVE-2023-4012?
To fix CVE-2023-4012, ensure that the NTP service is configured to handle NTS-enabled client requests properly.
3
What software versions are affected by CVE-2023-4012?
CVE-2023-4012 affects NTPsec version 1.2.2.
4
What happens if my server receives an NTS-enabled client request with CVE-2023-4012?
If your server is not NTS-enabled, it will crash upon receiving an NTS-enabled client request in mode 3.
5
Is this vulnerability specific to NTPsec software?
Yes, CVE-2023-4012 specifically affects the NTPsec software implementation.