CVE-2015-7871

CRITICAL

NTP <4.2.8p4, <4.3.77 - Auth Bypass

Title source: llm

Description

Crypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to bypass authentication.

Exploits (1)

metasploit WORKING POC
by Matthew Van Gundy of Cisco ASIG · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/ntp/ntp_nak_to_the_future.rb

Scores

CVSS v3 9.8
EPSS 0.7962
EPSS Percentile 99.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-287
Status published
Products (9)
debian/debian_linux 7.0
debian/debian_linux 8.0
debian/debian_linux 9.0
netapp/clustered_data_ontap
netapp/data_ontap
netapp/oncommand_balance
netapp/oncommand_performance_manager
netapp/oncommand_unified_manager
ntp/ntp 4.2.5 p186 (42 CPE variants)
Published Aug 07, 2017
Tracked Since Feb 18, 2026