⚠ Exploited in the wild
Exploitation observed in the wild. Not yet on CISA KEV.
Severity
5.0MEDIUMNVD
EPSS
92.1%
top 0.29%
CISA KEV
Not in KEV
Exploit
Exploited in wild
Active exploitation observed
Affected products
Timeline
PublishedJan 2
Latest updateDec 17

Description

The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service (traffic amplification) via forged (1) REQ_MON_GETLIST or (2) REQ_MON_GETLIST_1 requests, as exploited in the wild in December 2013.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages4 packages

NVDntp/ntp< 4.2.7+1
Debianntp/ntp< 1:4.2.8p3+dfsg-1
NVDoracle/linux6, 7+1

Patches

🔴Vulnerability Details

4
GHSA
GHSA-2q29-vhpq-hpv3: The monlist feature in ntp_request2022-05-14
OSV
CVE-2013-5211: The monlist feature in ntp_request2014-01-02
CVEList
CVE-2013-5211: The monlist feature in ntp_request2014-01-02
VulnCheck
opensuse opensuse Improper Input Validation2013

💥Exploits & PoCs

11
Exploit-DB
NTP ntpd monlist Query Reflection - Denial of Service2014-04-28
Metasploit
NTP Monitor List Scanner
Metasploit
NTP Mode 7 PEER_LIST DoS Scanner
Metasploit
NTP Mode 7 GET_RESTRICT DRDoS Scanner
Metasploit
NTP Mode 6 UNSETTRAP DRDoS Scanner

📋Vendor Advisories

6
CISA ICS
Hitachi Energy TropOS Devices Series 1400/2400/64002024-12-17
CISA ICS
NTP Reflection Attack2018-09-06
BSD
FreeBSD-SA-14:02.ntpd: ntpd distributed reflection Denial of Service vulnerability2014-01-14
Cisco
Network Time Foundation ntpd Service Network Traffic Amplification Issue2014-01-09
Debian
CVE-2013-5211: ntp - The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remot...2013

🕵️Threat Intelligence

1
Fortinet
Ransomware in Education: Analyzing Today’s Threats | FortiGuard Labs2021-10-05

📐Framework References

3
CWE
Asymmetric Resource Consumption (Amplification)
CWE
Insufficient Control of Network Message Volume (Network Amplification)
CWE
Incorrectly Specified Destination in a Communication Channel

💬Community

2
Bugzilla
CVE-2013-5211 ntp: DoS in monlist feature in ntpd2014-01-02
Bugzilla
CVE-2013-5211 ntp: DoS in monlist feature in ntpd [fedora-all]2014-01-02
CVE-2013-5211 — Improper Input Validation in NTP | cvebase