CVE-2015-7871

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
07/08/2017
Last modified:
20/04/2025

Description

Crypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to bypass authentication.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ntp:ntp:*:*:*:*:*:*:*:* 4.2.6 (including) 4.2.8 (excluding)
cpe:2.3:a:ntp:ntp:*:*:*:*:*:*:*:* 4.3.0 (including) 4.3.77 (excluding)
cpe:2.3:a:ntp:ntp:4.2.5:p186:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p187:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p188:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p189:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p190:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p191:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p192:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p193:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p194:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p195:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p196:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p197:*:*:*:*:*:*
cpe:2.3:a:ntp:ntp:4.2.5:p198:*:*:*:*:*:*