Database/Control plane, storage & DevOps
ntpd (protocol engine, zero-origin timestamp): Continually sending packets with a zero-origin timestamp lets a remote
Impact
Continually sending packets with a zero-origin timestamp lets a remote attacker disrupt an ntpd peer association. Cheap, stateless, and it needs nothing but the ability to send UDP to port 123 — which is open on far more cluster nodes than operators realise, because NTP is usually configured once at image-build time and never reviewed.
Who can reach it
Remote, unauthenticated — UDP packets to the NTP port.
What to do
Upgrade ntp to 4.2.8p11 or later and restart. Also firewall UDP/123 so only your internal time servers can reach cluster nodes — a host or fabric ACL change, applied live, that removes most of the NTP attack surface at once.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.