CVE-2013-5211
published 2014-01-02CVE-2013-5211: The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service (traffic amplification) via forged (1)…
PriorityP271medium5CVSS 2.0
AVNACLAuNCNINAP
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
97.76%
99.9th percentile
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service (traffic amplification) via forged (1) REQ_MON_GETLIST or (2) REQ_MON_GETLIST_1 requests, as exploited in the wild in December 2013.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ntp | < ntp 1:4.2.8p3+dfsg-1 (bullseye) | ntp 1:4.2.8p3+dfsg-1 (bullseye) |
| ntp | ntp | < 4.2.7 | 4.2.7 |
| ntp | ntp | — | — |
| ntp | ntp | >= 0 < 1:4.2.8p3+dfsg-1 | 1:4.2.8p3+dfsg-1 |
| opensuse | opensuse | — | — |
| oracle | linux | — | — |
| oracle | linux | — | — |
Detection & IOCsextracted from sources · hover to see the quote
bytes↗
rm_vn_mode=0x17; implementation=0x03; request=0x2a
- →Detect NTP monlist (REQ_MON_GETLIST) abuse by inspecting UDP/123 packets with NTP mode 7 (rm_vn_mode=0x17), implementation byte 0x03, and request byte 0x2a (decimal 42). ↗
- →Flag NTP servers responding to 'monlist' queries; the more clients in the list, the greater the amplification factor for DRDoS attacks. ↗
- →Alert on NTP mode 7 PEER_LIST responses that are larger in size or greater in quantity than the originating request, indicative of DRDoS amplification. ↗
- →Detect NTP mode 7 GET_RESTRICT (reslist) queries on UDP/123; responses revealing restriction lists can be abused for traffic amplification DRDoS. ↗
- →Detect NTP mode 6 UNSETTRAP requests; in some configurations servers respond with multiple packets, enabling DRDoS amplification via spoofed source IPs. ↗
- ·Vulnerability affects NTP versions before 4.2.7p26; upgrade to 4.2.7p26 or later to disable the monlist feature by default. ↗
- ·The attack exploits IP spoofing to reflect/amplify traffic; ingress filtering (BCP38) on network perimeters reduces the effectiveness of spoofed-source NTP amplification attacks. ↗
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vulncheck5.0MEDIUM
vendor_cisco5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Hitachi Energy TropOS Devices Series 1400/2400/6400
cisa_ics·2024-12-17·CVSS 5.0
[MEDIUM] Hitachi Energy TropOS Devices Series 1400/2400/6400
ICS Advisory
##
Hitachi Energy TropOS Devices Series 1400/2400/6400
Release DateDecember 17, 2024
Alert CodeICSA-24-352-02
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 5.3
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Hitachi Energy
- Equipment: TropOS Devices Series 1400/2400/6400
- Vulnerability: Improper Input Validation
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following products of Hitachi Energy are affected:
- TropOS devices series 1400/2400/6400: All versions prior to 8.9.6
## 3.2 Vulnerability Ov
CISA ICS
NTP Reflection Attack
cisa_ics·2018-09-06
NTP Reflection Attack
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
NTP Reflection Attack
Last RevisedSeptember 06, 2018
Alert CodeICSA-14-051-04
## OVERVIEW
NCCIC/ICS-CERT has been following the increase in denial-of-service (DoS) attacks using Network Time Protocol (NTP) Reflection. This type of attack provides an adversary the ability to generate high volume distributed denial of service (DDoS) traffic to target web sites or public‑facing devices that could cause disruption to services.
This vulnerability could be exploited remotely. Exploits that target this type of attack are known to be publicly available.
Mitigations are available for b
BSD
FreeBSD-SA-14:02.ntpd: ntpd distributed reflection Denial of Service vulnerability
bsd_advisories·2014-01-14·CVSS 5.0
CVE-2013-5211 [MEDIUM] FreeBSD-SA-14:02.ntpd: ntpd distributed reflection Denial of Service vulnerability
FreeBSD-SA-14:02.ntpd Security Advisory
The FreeBSD Project
Topic: ntpd distributed reflection Denial of Service vulnerability
Category: contrib
Module: ntpd
Announced: 2014-01-14
Affects: All supported versions of FreeBSD.
Corrected: 2014-01-14 19:04:33 UTC (stable/10, 10.0-PRERELEASE)
2014-01-14 19:12:40 UTC (releng/10.0, 10.0-RELEASE)
2014-01-14 19:12:40 UTC (releng/10.0, 10.0-RC5-p1)
2014-01-14 19:12:40 UTC (releng/10.0, 10.0-RC4-p1)
2014-01-14 19:12:40 UTC (releng/10.0, 10.0-RC3-p1)
2014-01-14 19:12:40 UTC (releng/10.0, 10.0-RC2-p1)
2014-01-14 19:12:40 UTC (releng/10.0, 10.0-RC1-p1)
2014-01-14 19:20:41 UTC (stable/9, 9.2-STABLE)
2014-01-14 19:42:28 UTC (releng/9.2, 9.2-RELEASE-p3)
2014-01-14 19:42:28 UTC (releng/9.1, 9.1-RELEASE-p10)
2014-01-14 19:20:41 UTC (stable/8, 8.4-STABLE)
20
Cisco
Network Time Foundation ntpd Service Network Traffic Amplification Issue
vendor_cisco·2014-01-09·CVSS 5.0
CVE-2013-5211 [MEDIUM] Network Time Foundation ntpd Service Network Traffic Amplification Issue
Network Time Foundation ntpd Service Network Traffic Amplification Issue
A vulnerability in the Network Time Protocol (NTP) package of several Cisco products could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.The vulnerability is due to processing MODE_PRIVATE (Mode 7) NTP control messages, which have a large amplification vector. An attacker could exploit this vulnerability by sending Mode 7 control requests to NTP servers and observing responses amplified up to 5,500 times in size. An exploit could allow the attacker to cause a DoS condition in which the affected NTP server is forced to process and respond with large response data.
Debian
CVE-2013-5211: ntp - The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remot...
vendor_debian·2013·CVSS 5.0
CVE-2013-5211 [MEDIUM] CVE-2013-5211: ntp - The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remot...
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service (traffic amplification) via forged (1) REQ_MON_GETLIST or (2) REQ_MON_GETLIST_1 requests, as exploited in the wild in December 2013.
Scope: local
bullseye: resolved (fixed in 1:4.2.8p3+dfsg-1)
Red Hat
ntp: DoS in monlist feature in ntpd
vendor_redhat·2010-04-20·CVSS 5.0
CVE-2013-5211 [MEDIUM] ntp: DoS in monlist feature in ntpd
ntp: DoS in monlist feature in ntpd
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service (traffic amplification) via forged (1) REQ_MON_GETLIST or (2) REQ_MON_GETLIST_1 requests, as exploited in the wild in December 2013.
Statement: This issue does not affect the default configuration of ntp packages shipped with Red Hat Enterprise Linux, which does not allow remote ntpd control queries. User changing ntpd access control configuration should consider reviewing additional information provided via https://bugzilla.redhat.com/show_bug.cgi?id=1047854#c27 to avoid exposing their systems to this traffic amplification issue.
Package: ntp (Red Hat Enterprise Linux 5) - Will not fix
Package: ntp (Red Hat Enterprise Linux 6) - W
Cisco
Network Time Foundation ntpd Service Network Traffic Amplification Issue
vendor_cisco
CVE-2013-5211 Network Time Foundation ntpd Service Network Traffic Amplification Issue
CVE-2013-5211: Network Time Foundation ntpd Service Network Traffic Amplification Issue
A vulnerability in the Network Time Protocol (NTP) package of several Cisco products could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to processing MODE_PRIVATE (Mode 7) NTP control messages, which have a large amplification vector. An attacker could exploit this vulnerability by sending Mode 7 control requests to NTP servers and observing responses amplified up to 5,500 times in size. An exploit could allow the attacker to cause a DoS condition in which the affected NTP server is forced to process and respond with large response data.
Bug IDs: CSCtd75033, CSCum52148, CSCum71311, CSCtd75033, CSCum52148
GHSA
GHSA-2q29-vhpq-hpv3: The monlist feature in ntp_request
ghsa_unreviewed·2022-05-14
CVE-2013-5211 [MEDIUM] CWE-20 GHSA-2q29-vhpq-hpv3: The monlist feature in ntp_request
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service (traffic amplification) via forged (1) REQ_MON_GETLIST or (2) REQ_MON_GETLIST_1 requests, as exploited in the wild in December 2013.
OSV
CVE-2013-5211: The monlist feature in ntp_request
osv·2014-01-02·CVSS 5.0
CVE-2013-5211 [MEDIUM] CVE-2013-5211: The monlist feature in ntp_request
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service (traffic amplification) via forged (1) REQ_MON_GETLIST or (2) REQ_MON_GETLIST_1 requests, as exploited in the wild in December 2013.
VulnCheck
opensuse opensuse Improper Input Validation
vulncheck·2013·CVSS 5.0
CVE-2013-5211 [MEDIUM] opensuse opensuse Improper Input Validation
opensuse opensuse Improper Input Validation
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service (traffic amplification) via forged (1) REQ_MON_GETLIST or (2) REQ_MON_GETLIST_1 requests, as exploited in the wild in December 2013.
Affected: opensuse opensuse
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://nvd.nist.gov/vuln/detail/CVE-2013-5211; https://www.cve.org/CVERecord?id=CVE-2013-5211
Exploit PoC: https://vulncheck.com/xdb/74d80e5ddeea; https://vulncheck.com/xdb/9e24428e659c
No detection rules found.
Exploit-DB
NTP ntpd monlist Query Reflection - Denial of Service
exploitdb·2014-04-28·CVSS 5.0
CVE-2013-5211 [MEDIUM] NTP ntpd monlist Query Reflection - Denial of Service
NTP ntpd monlist Query Reflection - Denial of Service
---
/*
* Exploit Title: CVE-2013-5211 PoC - NTP DDoS amplification
* Date: 28/04/2014
* Code Author: Danilo PC -
* CVE : CVE-2013-5211
*/
/* I coded this program to help other to understand how an DDoS attack amplified by NTP servers works (CVE-2013-5211)
* I took of the code that generates a DDoS, so this code only sends 1 packet. Why? Well...there's a lot of kiddies out there,
* if you know how to program, making a loop or using with other tool is piece of cake. There core idea is there, just use it as you please.
*/
//------------------------------------------------------------------------------------------------//
//------------------------------------------------------------------------------------------------//
#include //Fo
Metasploit
NTP Monitor List Scanner
metasploit
NTP Monitor List Scanner
NTP Monitor List Scanner
This module identifies NTP servers which permit "monlist" queries and obtains the recent clients list. The monlist feature allows remote attackers to cause a denial of service (traffic amplification) via spoofed requests. The more clients there are in the list, the greater the amplification.
Metasploit
NTP Mode 7 PEER_LIST DoS Scanner
metasploit
NTP Mode 7 PEER_LIST DoS Scanner
NTP Mode 7 PEER_LIST DoS Scanner
This module identifies NTP servers which permit "PEER_LIST" queries and return responses that are larger in size or greater in quantity than the request, allowing remote attackers to cause a distributed, reflected denial of service (aka, "DRDoS" or traffic amplification) via spoofed requests.
Metasploit
NTP Mode 7 GET_RESTRICT DRDoS Scanner
metasploit
NTP Mode 7 GET_RESTRICT DRDoS Scanner
NTP Mode 7 GET_RESTRICT DRDoS Scanner
This module identifies NTP servers which permit "reslist" queries and obtains the list of restrictions placed on various network interfaces, networks or hosts. The reslist feature allows remote attackers to cause a distributed, reflected denial of service (aka, "DRDoS" or traffic amplification) via spoofed requests. The more interfaces, networks or hosts with specific restrictions, the greater the amplification. requests.
Metasploit
NTP Mode 6 UNSETTRAP DRDoS Scanner
metasploit
NTP Mode 6 UNSETTRAP DRDoS Scanner
NTP Mode 6 UNSETTRAP DRDoS Scanner
This module identifies NTP servers which permit mode 6 UNSETTRAP requests that can be used to conduct DRDoS attacks. In some configurations, NTP servers will respond to UNSETTRAP requests with multiple packets, allowing remote attackers to cause a distributed, reflected denial of service (aka, "DRDoS" or traffic amplification) via spoofed requests.
Metasploit
Portmapper Amplification Scanner
metasploit
Portmapper Amplification Scanner
Portmapper Amplification Scanner
This module can be used to discover Portmapper services which can be used in an amplification DDoS attack against a third party.
Metasploit
NTP Clock Variables Disclosure
metasploit
NTP Clock Variables Disclosure
NTP Clock Variables Disclosure
This module reads the system internal NTP variables. These variables contain potentially sensitive information, such as the NTP software version, operating system version, peers, and more.
Metasploit
UDP Amplification Scanner
metasploit
UDP Amplification Scanner
UDP Amplification Scanner
Detect UDP endpoints with UDP amplification vulnerabilities
Metasploit
NTP Mode 7 PEER_LIST_SUM DoS Scanner
metasploit
NTP Mode 7 PEER_LIST_SUM DoS Scanner
NTP Mode 7 PEER_LIST_SUM DoS Scanner
This module identifies NTP servers which permit "PEER_LIST_SUM" queries and return responses that are larger in size or greater in quantity than the request, allowing remote attackers to cause a distributed, reflected denial of service (aka, "DRDoS" or traffic amplification) via spoofed requests.
Metasploit
NTP Mode 6 REQ_NONCE DRDoS Scanner
metasploit
NTP Mode 6 REQ_NONCE DRDoS Scanner
NTP Mode 6 REQ_NONCE DRDoS Scanner
This module identifies NTP servers which permit mode 6 REQ_NONCE requests that can be used to conduct DRDoS attacks. In some configurations, NTP servers will respond to REQ_NONCE requests with a response larger than the request, allowing remote attackers to cause a distributed, reflected denial of service (aka, "DRDoS" or traffic amplification) via spoofed requests.
Metasploit
SSDP ssdp:all M-SEARCH Amplification Scanner
metasploit
SSDP ssdp:all M-SEARCH Amplification Scanner
SSDP ssdp:all M-SEARCH Amplification Scanner
Discover SSDP amplification possibilities
Bugzilla
CVE-2013-5211 ntp: DoS in monlist feature in ntpd
bugzilla·2014-01-02·CVSS 5.0
CVE-2013-5211 [MEDIUM] CVE-2013-5211 ntp: DoS in monlist feature in ntpd
CVE-2013-5211 ntp: DoS in monlist feature in ntpd
Common Vulnerabilities and Exposures assigned an identifier CVE-2013-5211 to the following vulnerability:
Name: CVE-2013-5211
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5211
Assigned: 20130815
Reference: http://openwall.com/lists/oss-security/2013/12/30/6
Reference: http://openwall.com/lists/oss-security/2013/12/30/7
Reference: http://lists.ntp.org/pipermail/pool/2011-December/005616.html
Reference: http://bugs.ntp.org/show_bug.cgi?id=1532
Reference: http://www.eecis.udel.edu/~ntp/ntp_spool/ntp4/ntp-dev/ntp-dev-4.2.7p26.tar.gz
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service (traffic amplification) via forged (1) REQ_MON_GETLIST or (2) REQ_MON_GETLIS
Bugzilla
CVE-2013-5211 ntp: DoS in monlist feature in ntpd [fedora-all]
bugzilla·2014-01-02·CVSS 5.0
CVE-2013-5211 [MEDIUM] CVE-2013-5211 ntp: DoS in monlist feature in ntpd [fedora-all]
CVE-2013-5211 ntp: DoS in monlist feature in ntpd [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects multiple s
Fortinet
Ransomware in Education: Analyzing Today’s Threats | FortiGuard Labs
blogs_fortinet·2021-10-05
Ransomware in Education: Analyzing Today’s Threats | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
Ransomware in Education: Analyzing Today’s Threats
By Shunichi Imano | October 05, 2021
Several major ransomware incidents that impacted our daily lives occurred in 2021. In early May, Colonial Pipeline, the largest refined petroleum pipeline in the United States, was infected by DarkSide ransomware. The infection forced the company to shut down their pipeline as a precautionary measure while assessments were being made, leading to long lines of cars at gas stations along the East Coast. Later that same month, the REvil ransomware attacked JBS, the world’s largest meat processor, and disrupted the company’s meat productions. In July, REvil struck again, affecting customers of the managed services provider Kaseya. Attackers exploited an authentication bypas
CWE
Asymmetric Resource Consumption (Amplification)
mitre_cwe
CWE-405 Asymmetric Resource Consumption (Amplification)
CWE-405: Asymmetric Resource Consumption (Amplification)
The product does not properly control situations in which an adversary can cause the product to consume or produce excessive resources without requiring the adversary to invest equivalent work or otherwise prove authorization, i.e., the adversary's influence is "asymmetric."
This can lead to poor performance due to "amplification" of resource consumption, typically in a non-linear fashion. This situation is worsened if the product allows malicious users or attackers to consume more resources than their access level permits.
Modes of Introduction:
Phase: Architecture and Design
Phase: Implementation
Phase: Operation
Common Consequences:
Scope: Availability. Impact: DoS: Amplification, DoS: Resource Consumption (CPU), DoS: Resource
CWE
Insufficient Control of Network Message Volume (Network Amplification)
mitre_cwe
CWE-406 Insufficient Control of Network Message Volume (Network Amplification)
CWE-406: Insufficient Control of Network Message Volume (Network Amplification)
The product does not sufficiently monitor or control transmitted network traffic volume, so that an actor can cause the product to transmit more traffic than should be allowed for that actor.
In the absence of a policy to restrict asymmetric resource consumption, the application or system cannot distinguish between legitimate transmissions and traffic intended to serve as an amplifying attack on target systems. Systems can often be configured to restrict the amount of traffic sent out on behalf of a client, based on the client's origin or access level. This is usually defined in a resource allocation policy. In the absence of a mechanism to keep track of transmissions, the system or application can be easily
CWE
Incorrectly Specified Destination in a Communication Channel
mitre_cwe
CWE-941 Incorrectly Specified Destination in a Communication Channel
CWE-941: Incorrectly Specified Destination in a Communication Channel
The product creates a communication channel to initiate an outgoing request to an actor, but it does not correctly specify the intended destination for that actor.
Attackers at the destination may be able to spoof trusted servers to steal data or cause a denial of service. There are at least two distinct weaknesses that can cause the product to communicate with an unintended destination: If the product allows an attacker to control which destination is specified, then the attacker can cause it to connect to an untrusted or malicious destination. For example, because UDP is a connectionless protocol, UDP packets can be spoofed by specifying a false source address in the packet; when the server receives the packet and se
http://aix.software.ibm.com/aix/efixes/security/ntp_advisory.aschttp://bugs.ntp.org/show_bug.cgi?id=1532http://ics-cert.us-cert.gov/advisories/ICSA-14-051-04http://lists.ntp.org/pipermail/pool/2011-December/005616.htmlhttp://lists.opensuse.org/opensuse-updates/2014-09/msg00031.htmlhttp://marc.info/?l=bugtraq&m=138971294629419&w=2http://marc.info/?l=bugtraq&m=144182594518755&w=2http://openwall.com/lists/oss-security/2013/12/30/6http://openwall.com/lists/oss-security/2013/12/30/7http://secunia.com/advisories/59288http://secunia.com/advisories/59726http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095861http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095892http://www.eecis.udel.edu/~ntp/ntp_spool/ntp4/ntp-dev/ntp-dev-4.2.7p26.tar.gzhttp://www.kb.cert.org/vuls/id/348126http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.htmlhttp://www.securityfocus.com/bid/64692http://www.securitytracker.com/id/1030433http://www.us-cert.gov/ncas/alerts/TA14-013Ahttps://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04790232https://puppet.com/security/cve/puppetlabs-ntp-nov-2015-advisoryhttp://aix.software.ibm.com/aix/efixes/security/ntp_advisory.aschttp://bugs.ntp.org/show_bug.cgi?id=1532http://ics-cert.us-cert.gov/advisories/ICSA-14-051-04http://lists.ntp.org/pipermail/pool/2011-December/005616.htmlhttp://lists.opensuse.org/opensuse-updates/2014-09/msg00031.htmlhttp://marc.info/?l=bugtraq&m=138971294629419&w=2http://marc.info/?l=bugtraq&m=144182594518755&w=2http://openwall.com/lists/oss-security/2013/12/30/6http://openwall.com/lists/oss-security/2013/12/30/7http://secunia.com/advisories/59288http://secunia.com/advisories/59726http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095861http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095892http://www.eecis.udel.edu/~ntp/ntp_spool/ntp4/ntp-dev/ntp-dev-4.2.7p26.tar.gzhttp://www.kb.cert.org/vuls/id/348126http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.htmlhttp://www.securityfocus.com/bid/64692http://www.securitytracker.com/id/1030433http://www.us-cert.gov/ncas/alerts/TA14-013Ahttps://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04790232https://puppet.com/security/cve/puppetlabs-ntp-nov-2015-advisory
2014-01-02
Published
Exploited in the wild