CVE-2023-4012
ntpd will crash if the server is not NTS-enabled (no certificate) and it receives an NTS-enabled client request (mode 3).
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS probability
- 0.23%
- CWE
- CWE-372
- Published
- 2023-08-07
- Last modified
- 2026-06-22
Affected products
- NTPsec ntpsec
Weakness type
Related vulnerabilities
- CVE-2026-41388 — OpenClaw < 2026.3.31 - Configuration Rehydration via Empty-Array Revocation Handling
- CVE-2026-41340 — OpenClaw < 2026.3.31 - Authentication Boundary Bypass via Telegram Legacy allowFrom Migration
- CVE-2026-41300 — OpenClaw < 2026.3.31 - Preservation of Attacker-Discovered Endpoints in Remote Onboarding
- CVE-2023-36834 — Junos OS: SRX 4600 and SRX 5000 Series: The receipt of specific genuine packets by SRXes configured for L2 transparency will cause a DoS
- CVE-2023-31127 — DMTF-2023-0001: SPDM mutual authentication bypass
- CVE-2021-25735 — Validating Admission Webhook does not observe some previous fields
- CVE-2020-27222 — In Eclipse Californium version 2.3.0 to 2.6.0, the certificate based (x509 and RPK) DTLS handshakes...