CVE-2013-5211 is a denial-of-service vulnerability affecting NTP versions prior to 4.2.7p26, including various Linux distributions and Oracle products. It allows remote attackers to amplify traffic via forged monlist requests, leading to a denial of service. The vulnerability has a CVSS score of 5.0, indicating a network-based attack with low complexity and potential for partial availability impact. This CVE was actively exploited in the wild in December 2013, with public exploit code available in Metasploit and ExploitDB, and garnered significant community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.4CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:11.4:*:*:*:*:*:*:* | ||
< 4.2.7CPE matchmatch criteria | cpe:2.3:a:ntp:ntp:*:*:*:*:*:*:*:* | ||
4.2.7CPE matchmatch criteria | cpe:2.3:a:ntp:ntp:4.2.7:-:*:*:*:*:*:* | ||
4.2.7CPE matchmatch criteria | cpe:2.3:a:ntp:ntp:4.2.7:p0:*:*:*:*:*:* | ||
4.2.7CPE matchmatch criteria | cpe:2.3:a:ntp:ntp:4.2.7:p1:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.