Rapid7

vulnerability

NTP: Improper Input Validation (CVE-2015-5146)

Severity
4
CVSS
(AV:N/AC:M/Au:S/C:N/I:N/A:P)
Published
Aug 24, 2017
Added
Feb 23, 2023
Modified
Mar 1, 2023

Description

ntpd in ntp before 4.2.8p3 with remote configuration enabled allows remote authenticated users with knowledge of the configuration password and access to a computer entrusted to perform remote configuration to cause a denial of service (service crash) via a NULL byte in a crafted configuration directive packet.

Solution

ntp-upgrade-latest

References

    Title
    Rapid7 Labs

    2026 Global Threat Landscape Report

    The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.