Lucene search

K
f5F5F5:K17517
HistoryNov 06, 2015 - 12:00 a.m.

K17517 : NTP vulnerability CVE-2015-7701

2015-11-0600:00:00
my.f5.com
21

8.1 High

AI Score

Confidence

High

0.05 Low

EPSS

Percentile

92.9%

Security Advisory Description

Memory leak in the CRYPTO_ASSOC function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (memory consumption). (CVE-2015-7701)

Impact

An attacker could send packets tontpdthat may, after several days of ongoing attack, cause it to run out of memory. There is no control plane exposure in the BIG-IP system when you use a default configuration, and this issue is exposed only when NTP is configured to use the Autokey security protocol.?