7.8
CVSSv2

CVE-2016-6301

Published: 09/12/2016 Updated: 27/08/2020
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

The recv_and_process_client_pkt function in networking/ntpd.c in busybox allows remote malicious users to cause a denial of service (CPU and bandwidth consumption) via a forged NTP packet, which triggers a communication loop.

Vendor Advisories

Debian Bug report logs - #833442 busybox: CVE-2016-6301: NTP server denial of service flaw Package: src:busybox; Maintainer for src:busybox is Debian Install System Team <debian-boot@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 4 Aug 2016 12:24:23 UTC Severity: normal Tags: pat ...
The recv_and_process_client_pkt function in networking/ntpdc in busybox allows remote attackers to cause a denial of service (CPU and bandwidth consumption) via a forged NTP packet, which triggers a communication loop ...

Mailing Lists

SEC Consult Vulnerability Lab Security Advisory < 20200312-0 > ======================================================================= title: Authenticated Command Injection product: Phoenix Contact TC Router & TC Cloud Client vulnerable version: <=2053 & <=20317 & <=10317 fixed vers ...
SEC Consult Vulnerability Lab Security Advisory < 20200312-0 > ======================================================================= title: Authenticated Command Injection product: Phoenix Contact TC Router & TC Cloud Client vulnerable version: <=2053 & <=20317 & <=10317 fixed vers ...
SEC Consult Vulnerability Lab Security Advisory < 20200827-0 > ======================================================================= title: Multiple Vulnerabilities product: ZTE mobile Hotspot MS910S vulnerable version: DL_MF910S_CN_EUV10001 fixed version: - CVE number: CVE-2019-3422 ...
SEC Consult Vulnerability Lab Security Advisory < 20190904-0 > ======================================================================= title: Multiple vulnerabilities product: Cisco RV340, Cisco RV340W, Cisco RV345, Cisco RV345P, Cisco RV260, Cisco RV260P, Cisco RV260W, Cisco 160, ...
SEC Consult Vulnerability Lab Security Advisory < 20190612-0 > ======================================================================= title: Multiple vulnerabilities product: WAGO 852 Industrial Managed Switch Series vulnerable version: 852-303: <v122S0 852-1305: <v116S0 ...
Phoenix Contact TC Router and TC Cloud Client versions 2053 and below, 20317 and below, and 10317 and below suffer from authenticated command injection and various other vulnerabilities ...
SEC Consult Vulnerability Lab Security Advisory < 20190612-0 > ======================================================================= title: Multiple vulnerabilities product: WAGO 852 Industrial Managed Switch Series vulnerable version: 852-303: <v122S0 852-1305: <v116S0 ...
SEC Consult Vulnerability Lab Security Advisory < 20190904-0 > ======================================================================= title: Multiple vulnerabilities product: Cisco RV340, Cisco RV340W, Cisco RV345, Cisco RV345P, Cisco RV260, Cisco RV260P, Cisco RV260W, Cisco 160, ...
ZTE Mobile Hotspot MS910S version DL_MF910S_CN_EUV10001 suffers from having a hard-coded administrative password, busybox vulnerabilities, and having a known backdoor in the GoAhead webserver ...
Many Cisco devices such as Cisco RV340, Cisco RV340W, Cisco RV345, Cisco RV345P, Cisco RV260, Cisco RV260P, Cisco RV260W, Cisco 160, and Cisco 160W suffer from having hard-coded credentials, known GNU glibc, known BusyBox, and IoT Inspector identified vulnerabilities ...
The industrial managed switch series 852 from WAGO is affected by multiple vulnerabilities such as old software components embedded in the firmware Furthermore, hardcoded password hashes and credentials were also found by doing an automated scan with IoT Inspector ...