Lucene search

K
cve[email protected]CVE-2015-7871
HistoryAug 07, 2017 - 8:29 p.m.

CVE-2015-7871

2017-08-0720:29:00
CWE-287
web.nvd.nist.gov
238
21
ntp
cve-2015-7871
crypto-nak packets
authentication bypass
ntp 4.2.x
ntp 4.3.x
remote attack

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.3 High

AI Score

Confidence

High

0.97 High

EPSS

Percentile

99.8%

Crypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to bypass authentication.

Affected configurations

NVD
Node
ntpntpRange4.2.64.2.8
OR
ntpntpRange4.3.04.3.77
OR
ntpntpMatch4.2.5p186
OR
ntpntpMatch4.2.5p187
OR
ntpntpMatch4.2.5p188
OR
ntpntpMatch4.2.5p189
OR
ntpntpMatch4.2.5p190
OR
ntpntpMatch4.2.5p191
OR
ntpntpMatch4.2.5p192
OR
ntpntpMatch4.2.5p193
OR
ntpntpMatch4.2.5p194
OR
ntpntpMatch4.2.5p195
OR
ntpntpMatch4.2.5p196
OR
ntpntpMatch4.2.5p197
OR
ntpntpMatch4.2.5p198
OR
ntpntpMatch4.2.5p199
OR
ntpntpMatch4.2.5p200
OR
ntpntpMatch4.2.5p201
OR
ntpntpMatch4.2.5p202
OR
ntpntpMatch4.2.5p203
OR
ntpntpMatch4.2.5p204
OR
ntpntpMatch4.2.5p205
OR
ntpntpMatch4.2.5p206
OR
ntpntpMatch4.2.5p207
OR
ntpntpMatch4.2.5p208
OR
ntpntpMatch4.2.5p209
OR
ntpntpMatch4.2.5p210
OR
ntpntpMatch4.2.5p211
OR
ntpntpMatch4.2.5p212
OR
ntpntpMatch4.2.5p213
OR
ntpntpMatch4.2.5p214
OR
ntpntpMatch4.2.5p215
OR
ntpntpMatch4.2.5p216
OR
ntpntpMatch4.2.5p217
OR
ntpntpMatch4.2.5p218
OR
ntpntpMatch4.2.5p219
OR
ntpntpMatch4.2.5p220
OR
ntpntpMatch4.2.5p221
OR
ntpntpMatch4.2.5p222
OR
ntpntpMatch4.2.5p223
OR
ntpntpMatch4.2.5p224
OR
ntpntpMatch4.2.5p225
OR
ntpntpMatch4.2.5p226
OR
ntpntpMatch4.2.5p227
OR
ntpntpMatch4.2.5p228
OR
ntpntpMatch4.2.5p229
OR
ntpntpMatch4.2.5p230
OR
ntpntpMatch4.2.5p231_rc1
OR
ntpntpMatch4.2.5p232_rc1
OR
ntpntpMatch4.2.5p233_rc1
OR
ntpntpMatch4.2.5p234_rc1
OR
ntpntpMatch4.2.5p235_rc1
OR
ntpntpMatch4.2.5p236_rc1
OR
ntpntpMatch4.2.5p237_rc1
OR
ntpntpMatch4.2.5p238_rc1
OR
ntpntpMatch4.2.5p239_rc1
OR
ntpntpMatch4.2.5p240_rc1
OR
ntpntpMatch4.2.5p241_rc1
OR
ntpntpMatch4.2.5p242_rc1
OR
ntpntpMatch4.2.5p243_rc1
OR
ntpntpMatch4.2.5p244_rc1
OR
ntpntpMatch4.2.5p245_rc1
OR
ntpntpMatch4.2.5p246_rc1
OR
ntpntpMatch4.2.5p247_rc1
OR
ntpntpMatch4.2.5p248_rc1
OR
ntpntpMatch4.2.5p249_rc1
OR
ntpntpMatch4.2.5p250_rc1
OR
ntpntpMatch4.2.8p1
OR
ntpntpMatch4.2.8p1-beta1
OR
ntpntpMatch4.2.8p1-beta2
OR
ntpntpMatch4.2.8p1-beta3
OR
ntpntpMatch4.2.8p1-beta4
OR
ntpntpMatch4.2.8p1-beta5
OR
ntpntpMatch4.2.8p1-rc1
OR
ntpntpMatch4.2.8p1-rc2
OR
ntpntpMatch4.2.8p2
OR
ntpntpMatch4.2.8p2-rc1
OR
ntpntpMatch4.2.8p2-rc2
OR
ntpntpMatch4.2.8p2-rc3
OR
ntpntpMatch4.2.8p3
OR
ntpntpMatch4.2.8p3-rc1
OR
ntpntpMatch4.2.8p3-rc2
OR
ntpntpMatch4.2.8p3-rc3
Node
debiandebian_linuxMatch7.0
OR
debiandebian_linuxMatch8.0
OR
debiandebian_linuxMatch9.0
Node
netapponcommand_balanceMatch-
OR
netapponcommand_performance_managerMatch-
OR
netapponcommand_unified_managerMatch-clustered_data_ontap
OR
netappclustered_data_ontapMatch-
OR
netappdata_ontapMatch-7-mode

Social References

More

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.3 High

AI Score

Confidence

High

0.97 High

EPSS

Percentile

99.8%