CVE-2015-7871
CRITICALNTP <4.2.8p4, <4.3.77 - Auth Bypass
Title source: llmDescription
Crypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to bypass authentication.
Exploits (1)
metasploit
WORKING POC
by Matthew Van Gundy of Cisco ASIG · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/ntp/ntp_nak_to_the_future.rb
References (10)
Scores
CVSS v3
9.8
EPSS
0.7962
EPSS Percentile
99.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-287
Status
published
Products (9)
debian/debian_linux
7.0
debian/debian_linux
8.0
debian/debian_linux
9.0
netapp/clustered_data_ontap
netapp/data_ontap
netapp/oncommand_balance
netapp/oncommand_performance_manager
netapp/oncommand_unified_manager
ntp/ntp
4.2.5 p186 (42 CPE variants)
Published
Aug 07, 2017
Tracked Since
Feb 18, 2026