Exploitation Summary
EIP tracks 1 public exploit for CVE-2015-7871.
PoCs published by Matthew Van Gundy of Cisco ASIG, including Metasploit module auxiliary/scanner/ntp/ntp_nak_to_the_future.
AI-analyzed exploit summary This Metasploit module exploits CVE-2015-7871 in NTP by sending Crypto-NAK packets to bypass authentication and establish a symmetric association, potentially allowing time manipulation.
Description
Crypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to bypass authentication.
Exploits (1)
metasploit
WORKING POC
by Matthew Van Gundy of Cisco ASIG · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/ntp/ntp_nak_to_the_future.rb
This Metasploit module exploits CVE-2015-7871 in NTP by sending Crypto-NAK packets to bypass authentication and establish a symmetric association, potentially allowing time manipulation.
Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target:
NTP (Network Time Protocol) daemons (ntpd)
No auth needed
Prerequisites:
Network access to the target NTP server · UDP port 123 accessibility
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
References (10)
Core 10
Core References
Vendor Advisory x_refsource_confirm
http://support.ntp.org/bin/view/Main/NtpBug2941
Issue Tracking, Third Party Advisory, VDB Entry x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1274265
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1033951
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2015/dsa-3388
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/77287
Third Party Advisory, VDB Entry vendor-advisory
x_refsource_gentoo
https://security.gentoo.org/glsa/201604-03
Third Party Advisory, VDB Entry x_refsource_confirm
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05270839
Third Party Advisory, VDB Entry vendor-advisory
x_refsource_gentoo
https://security.gentoo.org/glsa/201607-15
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20171004-0001/
Vendor Advisory x_refsource_confirm
https://cert-portal.siemens.com/productcert/pdf/ssa-497656.pdf
Scores
CVSS v3
9.8
EPSS
0.8358
EPSS Percentile
99.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-287
Status
published
Products (9)
debian/debian_linux
7.0
debian/debian_linux
8.0
debian/debian_linux
9.0
netapp/clustered_data_ontap
netapp/data_ontap
netapp/oncommand_balance
netapp/oncommand_performance_manager
netapp/oncommand_unified_manager
ntp/ntp
4.2.5 p186 (42 CPE variants)
Published
Aug 07, 2017
Tracked Since
Feb 18, 2026