405
VMScore

CVE-2015-7855

Published: 07/08/2017 Updated: 19/04/2021
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 405
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

The decodenetnum function in ntpd in NTP 4.2.x prior to 4.2.8p4, and 4.3.x prior to 4.3.77 allows remote malicious users to cause a denial of service (assertion failure) via a 6 or mode 7 packet containing a long data value.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ntp ntp

ntp ntp 4.2.8

debian debian linux 7.0

debian debian linux 8.0

debian debian linux 9.0

netapp oncommand balance -

netapp oncommand performance manager -

netapp oncommand unified manager -

netapp clustered data ontap -

netapp data ontap -

siemens tim_4r-ie_firmware

siemens tim_4r-ie_dnp3_firmware

Vendor Advisories

Several security issues were fixed in NTP ...
Several vulnerabilities were discovered in the Network Time Protocol daemon and utility programs: CVE-2015-5146 A flaw was found in the way ntpd processed certain remote configuration packets An attacker could use a specially crafted package to cause ntpd to crash if: ntpd enabled remote configuration The attacker had the ...
The decodenetnum function in ntpd in NTP 42x before 428p4, and 43x before 4377 allows remote attackers to cause a denial of service (assertion failure) via a 6 or mode 7 packet containing a long data value ...
Multiple Cisco products incorporate a version of the ntpd package Versions of this package are affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to create a denial of service (DoS) condition or modify the time being advertised by a device acting as a network time protocol (NTP) server On October 21st, 2 ...

Exploits

#!/usr/bin/env python # Exploit Title: ntpd 428p3 remote DoS # Date: 2015-10-21 # Bug Discovery: John D "Doug" Birdwell # Exploit Author: Magnus Klaaborg Stubman (@magnusstubman) # Website: supportntporg/bin/view/Main/NtpBug2922 # Vendor Homepage: wwwntporg/ # Software Link: wwweecisudeledu/~ntp/ntp_spool/ntp4/ntp-4 ...
NTP version 428p3 suffers from a denial of service vulnerability ...