CVE-2015-7705
9.8
CRITICAL · CVSS 3.1 · EPSS 12.4% (pctl 96)
Patch early
EPSS 12.4% — above the 10% action threshold.
Description
The rate limiting feature in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to have unspecified impact via a large number of crafted requests.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 12.35% — more likely to be exploited than 96% of all CVEs |
| Weakness | CWE-20 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2017-08-07 |
| Last modified | 2026-06-17 |
Affected (10)
| Vendor | Product |
|---|---|
| citrix | xenserver |
| netapp | clustered data ontap |
| netapp | data ontap |
| netapp | oncommand performance manager |
| netapp | oncommand unified manager |
| ntp | ntp |
| siemens | tim 4r-ie |
| siemens | tim 4r-ie dnp3 |
| siemens | tim 4r-ie dnp3 firmware |
| siemens | tim 4r-ie firmware |
References
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00020.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00034.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00037.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00048.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00052.html
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00020.html
- http://lists.opensuse.org/opensuse-security-announce/2016-07/msg00026.html
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00042.html
- http://lists.opensuse.org/opensuse-updates/2015-11/msg00093.html
- http://lists.opensuse.org/opensuse-updates/2016-05/msg00114.html
- http://packetstormsecurity.com/files/134137/Slackware-Security-Advisory-ntp-Updates.html
- http://support.ntp.org/bin/view/Main/NtpBug2901
- http://support.ntp.org/bin/view/Main/SecurityNotice#October_2015_NTP_4_2_8p4_Securit
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151021-ntp
- http://www.securityfocus.com/archive/1/536737/100/0/threaded
- http://www.securityfocus.com/archive/1/536796/100/0/threaded
- http://www.securityfocus.com/archive/1/archive/1/536737/100/100/threaded
- http://www.securityfocus.com/archive/1/archive/1/536796/100/100/threaded
- http://www.securityfocus.com/bid/77284
→ the Explorer · watch your stack · NVD