vulnerability

Huawei EulerOS: CVE-2015-7703: ntp security update

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:P/A:N)
Published
Jul 24, 2017
Added
Nov 30, 2017
Modified
Aug 13, 2025

Description

It was found that NTP's :config command could be used to set the pidfile and driftfile paths without any restrictions. A remote attacker could use this flaw to overwrite a file on the file system with a file containing the pid of the ntpd process (immediately) or the current estimated drift of the system clock (in hourly intervals).

Solutions

huawei-euleros-2_0_sp1-upgrade-ntphuawei-euleros-2_0_sp1-upgrade-ntpdate
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.