CVE-2015-7871

CRITICAL

NTP <4.2.8p4, <4.3.77 - Auth Bypass

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2015-7871. PoCs published by Matthew Van Gundy of Cisco ASIG, including Metasploit module auxiliary/scanner/ntp/ntp_nak_to_the_future.

AI-analyzed exploit summary This Metasploit module exploits CVE-2015-7871 in NTP by sending Crypto-NAK packets to bypass authentication and establish a symmetric association, potentially allowing time manipulation.

Description

Crypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to bypass authentication.

Exploits (1)

metasploit WORKING POC
by Matthew Van Gundy of Cisco ASIG · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/ntp/ntp_nak_to_the_future.rb

This Metasploit module exploits CVE-2015-7871 in NTP by sending Crypto-NAK packets to bypass authentication and establish a symmetric association, potentially allowing time manipulation.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: NTP (Network Time Protocol) daemons (ntpd)
No auth needed
Prerequisites: Network access to the target NTP server · UDP port 123 accessibility
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (10)

Core 10
Core References
Vendor Advisory x_refsource_confirm
http://support.ntp.org/bin/view/Main/NtpBug2941
Issue Tracking, Third Party Advisory, VDB Entry x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1274265
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1033951
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2015/dsa-3388
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/77287
Third Party Advisory, VDB Entry vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201604-03
Third Party Advisory, VDB Entry vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201607-15
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20171004-0001/

Scores

CVSS v3 9.8
EPSS 0.8358
EPSS Percentile 99.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-287
Status published
Products (9)
debian/debian_linux 7.0
debian/debian_linux 8.0
debian/debian_linux 9.0
netapp/clustered_data_ontap
netapp/data_ontap
netapp/oncommand_balance
netapp/oncommand_performance_manager
netapp/oncommand_unified_manager
ntp/ntp 4.2.5 p186 (42 CPE variants)
Published Aug 07, 2017
Tracked Since Feb 18, 2026