vendor:
ntpsec
by:
Magnus Klaaborg Stubman
6.5
CVSS
MEDIUM
authenticated NULL pointer exception
NULL Pointer Dereference
CWE
Product Name: ntpsec
Affected Version From: 1.1.2000
Affected Version To: 1.1.2002
Patch Exists: NO
Related CWE: CVE-2019-6445
CPE: a:ntpsec_project:ntpsec:1.1.0cpe:/a:ntpsec_project:ntpsec:1.1.1cpe:/a:ntpsec_project:ntpsec:1.1.2
Platforms Tested:
2019
ntpsec 1.1.2 authenticated NULL pointer exception Proof of concept
This exploit allows an attacker to trigger a NULL pointer exception in ntpsec version 1.1.2, causing a denial-of-service condition. The vulnerability is authenticated, meaning that the attacker must provide valid credentials to exploit it. The exploit sends a specially crafted packet to the target server, triggering the NULL pointer exception.
Mitigation:
Update to a version of ntpsec that is not affected by this vulnerability. Alternatively, disable the vulnerable functionality if it is not needed.