7.5
CVSSv3

CVE-2023-3036

Published: 14/06/2023 Updated: 27/06/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

An unchecked read in NTP server in github.com/cloudflare/cfnts prior to commit 783490b github.com/cloudflare/cfnts/commit/783490b913f05e508a492cd7b02e3c4ec2297b71  enabled a remote malicious user to trigger a panic by sending an NTSAuthenticator packet with extension length longer than the packet contents.

Vulnerable Product Search on Vulmon Subscribe to Product

cloudflare cfnts