Network Time Protocol (NTP) Mode 6 Scanner

medium Nessus Plugin ID 97861

Synopsis

The remote NTP server responds to mode 6 queries.

Description

The remote NTP server responds to mode 6 queries. Devices that respond to these queries have the potential to be used in NTP amplification attacks. An unauthenticated, remote attacker could potentially exploit this, via a specially crafted mode 6 query, to cause a reflected denial of service condition.

Solution

Restrict NTP mode 6 queries.

See Also

https://ntpscan.shadowserver.org

Plugin Details

Severity: Medium

ID: 97861

File Name: ntp_mode6_query.nasl

Version: 1.2

Type: remote

Family: Misc.

Published: 3/21/2017

Updated: 5/7/2018

Supported Sensors: Nessus

Risk Information

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS v3

Risk Factor: Medium

Base Score: 5.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L

Vulnerability Information

Required KB Items: Services/udp/ntp