Denial of Service Vulnerability in NTP by ntpd
CVE-2015-5195

7.5HIGH

Key Information:

Status
Vendor
CVE Published:
21 July 2017

Badges

👾 Exploit Exists🟣 EPSS 10%

Summary

A vulnerability in ntpd, part of NTP, allows remote attackers to trigger a denial of service by sending specially crafted configuration commands, leading to segmentation faults. This flaw can occur if specific configuration commands are not enabled at the time of compilation, potentially disrupting time synchronization services.

References

EPSS Score

10% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability Reserved

.