CVE-2015-7979
ntp: off-path denial of service on authenticated broadcast mode
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (client-server association tear down) by sending broadcast packets with invalid authentication to a broadcast client.
NTP en versiones anteriores a 4.2.8p6 y 4.3.x en versiones anteriores a 4.3.90 permite a atacantes remotos causar una denegación de servicio (asociación cliente-servidor) por el envío de paquetes de difusión con autenticación no válida a un cliente transmisor.
It was found that when NTP was configured in broadcast mode, a remote attacker could broadcast packets with bad authentication to all clients. The clients, upon receiving the malformed packets, would break the association with the broadcast server, causing them to become out of sync over a longer period of time.
The Network Time Protocol is used to synchronize a computer's time with another referenced time source. These packages include the ntpd service which continuously adjusts system time and utilities used to query and configure the ntpd service. Security Fix: It was found that the fix for CVE-2014-9750 was incomplete: three issues were found in the value length checks in NTP's ntp_crypto.c, where a packet with particular autokey operations that contained malicious data was not always being completely validated. A remote attacker could use a specially crafted NTP packet to crash ntpd.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-10-23 CVE Reserved
- 2016-02-25 CVE Published
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-19: Data Processing Errors
- CWE-20: Improper Input Validation
CAPEC
References (31)
URL | Tag | Source |
---|---|---|
http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html | X_refsource_confirm |
|
http://www.securityfocus.com/bid/81816 | Third Party Advisory | |
http://www.securitytracker.com/id/1034782 | Third Party Advisory | |
https://bto.bluecoat.com/security-advisory/sa113 | Third Party Advisory | |
https://cert-portal.siemens.com/productcert/pdf/ssa-497656.pdf | X_refsource_confirm |
|
https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03750en_us | X_refsource_confirm | |
https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03766en_us | X_refsource_confirm | |
https://security.netapp.com/advisory/ntap-20171031-0001 | X_refsource_confirm |
|
https://us-cert.cisa.gov/ics/advisories/icsa-21-103-11 | X_refsource_misc | |
https://www.kb.cert.org/vuls/id/718152 | Third Party Advisory |
|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | <= 4.2.8 Search vendor "Ntp" for product "Ntp" and version " <= 4.2.8" | p5 |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.0 Search vendor "Ntp" for product "Ntp" and version "4.3.0" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.1 Search vendor "Ntp" for product "Ntp" and version "4.3.1" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.2 Search vendor "Ntp" for product "Ntp" and version "4.3.2" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.3 Search vendor "Ntp" for product "Ntp" and version "4.3.3" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.4 Search vendor "Ntp" for product "Ntp" and version "4.3.4" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.5 Search vendor "Ntp" for product "Ntp" and version "4.3.5" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.6 Search vendor "Ntp" for product "Ntp" and version "4.3.6" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.7 Search vendor "Ntp" for product "Ntp" and version "4.3.7" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.8 Search vendor "Ntp" for product "Ntp" and version "4.3.8" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.10 Search vendor "Ntp" for product "Ntp" and version "4.3.10" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.11 Search vendor "Ntp" for product "Ntp" and version "4.3.11" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.12 Search vendor "Ntp" for product "Ntp" and version "4.3.12" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.13 Search vendor "Ntp" for product "Ntp" and version "4.3.13" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.14 Search vendor "Ntp" for product "Ntp" and version "4.3.14" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.15 Search vendor "Ntp" for product "Ntp" and version "4.3.15" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.16 Search vendor "Ntp" for product "Ntp" and version "4.3.16" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.17 Search vendor "Ntp" for product "Ntp" and version "4.3.17" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.18 Search vendor "Ntp" for product "Ntp" and version "4.3.18" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.19 Search vendor "Ntp" for product "Ntp" and version "4.3.19" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.20 Search vendor "Ntp" for product "Ntp" and version "4.3.20" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.21 Search vendor "Ntp" for product "Ntp" and version "4.3.21" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.22 Search vendor "Ntp" for product "Ntp" and version "4.3.22" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.23 Search vendor "Ntp" for product "Ntp" and version "4.3.23" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.24 Search vendor "Ntp" for product "Ntp" and version "4.3.24" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.25 Search vendor "Ntp" for product "Ntp" and version "4.3.25" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.26 Search vendor "Ntp" for product "Ntp" and version "4.3.26" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.27 Search vendor "Ntp" for product "Ntp" and version "4.3.27" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.28 Search vendor "Ntp" for product "Ntp" and version "4.3.28" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.29 Search vendor "Ntp" for product "Ntp" and version "4.3.29" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.30 Search vendor "Ntp" for product "Ntp" and version "4.3.30" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.31 Search vendor "Ntp" for product "Ntp" and version "4.3.31" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.32 Search vendor "Ntp" for product "Ntp" and version "4.3.32" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.33 Search vendor "Ntp" for product "Ntp" and version "4.3.33" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.34 Search vendor "Ntp" for product "Ntp" and version "4.3.34" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.35 Search vendor "Ntp" for product "Ntp" and version "4.3.35" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.36 Search vendor "Ntp" for product "Ntp" and version "4.3.36" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.37 Search vendor "Ntp" for product "Ntp" and version "4.3.37" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.38 Search vendor "Ntp" for product "Ntp" and version "4.3.38" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.39 Search vendor "Ntp" for product "Ntp" and version "4.3.39" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.40 Search vendor "Ntp" for product "Ntp" and version "4.3.40" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.41 Search vendor "Ntp" for product "Ntp" and version "4.3.41" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.42 Search vendor "Ntp" for product "Ntp" and version "4.3.42" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.43 Search vendor "Ntp" for product "Ntp" and version "4.3.43" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.44 Search vendor "Ntp" for product "Ntp" and version "4.3.44" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.45 Search vendor "Ntp" for product "Ntp" and version "4.3.45" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.46 Search vendor "Ntp" for product "Ntp" and version "4.3.46" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.47 Search vendor "Ntp" for product "Ntp" and version "4.3.47" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.48 Search vendor "Ntp" for product "Ntp" and version "4.3.48" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.49 Search vendor "Ntp" for product "Ntp" and version "4.3.49" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.50 Search vendor "Ntp" for product "Ntp" and version "4.3.50" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.51 Search vendor "Ntp" for product "Ntp" and version "4.3.51" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.52 Search vendor "Ntp" for product "Ntp" and version "4.3.52" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.53 Search vendor "Ntp" for product "Ntp" and version "4.3.53" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.54 Search vendor "Ntp" for product "Ntp" and version "4.3.54" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.55 Search vendor "Ntp" for product "Ntp" and version "4.3.55" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.56 Search vendor "Ntp" for product "Ntp" and version "4.3.56" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.57 Search vendor "Ntp" for product "Ntp" and version "4.3.57" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.58 Search vendor "Ntp" for product "Ntp" and version "4.3.58" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.59 Search vendor "Ntp" for product "Ntp" and version "4.3.59" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.60 Search vendor "Ntp" for product "Ntp" and version "4.3.60" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.61 Search vendor "Ntp" for product "Ntp" and version "4.3.61" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.62 Search vendor "Ntp" for product "Ntp" and version "4.3.62" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.63 Search vendor "Ntp" for product "Ntp" and version "4.3.63" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.64 Search vendor "Ntp" for product "Ntp" and version "4.3.64" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.65 Search vendor "Ntp" for product "Ntp" and version "4.3.65" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.66 Search vendor "Ntp" for product "Ntp" and version "4.3.66" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.67 Search vendor "Ntp" for product "Ntp" and version "4.3.67" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.68 Search vendor "Ntp" for product "Ntp" and version "4.3.68" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.69 Search vendor "Ntp" for product "Ntp" and version "4.3.69" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.70 Search vendor "Ntp" for product "Ntp" and version "4.3.70" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.71 Search vendor "Ntp" for product "Ntp" and version "4.3.71" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.72 Search vendor "Ntp" for product "Ntp" and version "4.3.72" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.73 Search vendor "Ntp" for product "Ntp" and version "4.3.73" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.74 Search vendor "Ntp" for product "Ntp" and version "4.3.74" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.75 Search vendor "Ntp" for product "Ntp" and version "4.3.75" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.76 Search vendor "Ntp" for product "Ntp" and version "4.3.76" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.77 Search vendor "Ntp" for product "Ntp" and version "4.3.77" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.78 Search vendor "Ntp" for product "Ntp" and version "4.3.78" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.79 Search vendor "Ntp" for product "Ntp" and version "4.3.79" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.80 Search vendor "Ntp" for product "Ntp" and version "4.3.80" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.81 Search vendor "Ntp" for product "Ntp" and version "4.3.81" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.82 Search vendor "Ntp" for product "Ntp" and version "4.3.82" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.83 Search vendor "Ntp" for product "Ntp" and version "4.3.83" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.84 Search vendor "Ntp" for product "Ntp" and version "4.3.84" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.85 Search vendor "Ntp" for product "Ntp" and version "4.3.85" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.86 Search vendor "Ntp" for product "Ntp" and version "4.3.86" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.87 Search vendor "Ntp" for product "Ntp" and version "4.3.87" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.88 Search vendor "Ntp" for product "Ntp" and version "4.3.88" | - |
Affected
| ||||||
Ntp Search vendor "Ntp" | Ntp Search vendor "Ntp" for product "Ntp" | 4.3.89 Search vendor "Ntp" for product "Ntp" and version "4.3.89" | - |
Affected
|