cbcvebase.
CVE-2015-7704
published 2017-08-07

CVE-2015-7704: The ntpd client in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service via a number of crafted "KOD" messages.

PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
10.95%
95.4th percentile
The ntpd client in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service via a number of crafted "KOD" messages.

Affected

70 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
ciscoproducts_october_2015
citrixcitrix_adm
citrixcitrix_hypervisor
citrixcitrix_virtual_apps_and_desktops
citrixendpoint_management
citrixnetscaler_adc
citrixnetscaler_gateway
citrixxenserver
citrixxenserver
citrixxenserver
citrixxenserver
citrixxenserver
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianntp< ntp 1:4.2.8p4+dfsg-3 (bullseye)ntp 1:4.2.8p4+dfsg-3 (bullseye)
debianntp< ntp 1:4.2.8p11+dfsg-1 (bullseye)ntp 1:4.2.8p11+dfsg-1 (bullseye)
debianntpsec< ntp 1:4.2.8p11+dfsg-1 (bullseye)ntp 1:4.2.8p11+dfsg-1 (bullseye)
mcafeeenterprise_security_manager< 10.4.010.4.0
mcafeeenterprise_security_manager>= 11.0.0 < 11.2.011.2.0
ntpntp

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_cisco7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.