Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2015-5300

22
FAUCET Score

CVE-2015-5300 describes a vulnerability in NTP versions prior to 4.2.8p5, specifically within the panic_gate check, affecting products from vendors like Canonical, Debian, and Red Hat. This flaw allows remote attackers to manipulate system time, either by setting an arbitrary time when NTP is started with the -g option, or by altering the time by up to 900 seconds through responding to trusted requests, leading to a denial of service due to an abort and restart. With a CVSS score of 7.5 (High), the vulnerability is network-exploitable with low attack complexity, resulting in a high impact on availability. While there is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB) is unavailable, and community discussion is minimal, though it has received some media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
21CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:*
22CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*
11CPE matchmatch criteria
cpe:2.3:a:suse:linux_enterprise_debuginfo:11:sp2:*:*:*:*:*:*
11CPE matchmatch criteria
cpe:2.3:a:suse:linux_enterprise_debuginfo:11:sp3:*:*:*:*:*:*
11CPE matchmatch criteria
cpe:2.3:a:suse:linux_enterprise_debuginfo:11:sp4:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

7.5HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.0

Exploit Intelligence

EPSS Score
9.13%
Probability of exploitation in next 30 days
EPSS Percentile
94.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
This CVE's current EPSS score of 0.0913 is in the 92nd percentile among its peer group of 51,466 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: ntp-0:4.2.6p5-5.el6_7.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: ntp-0:4.2.6p5-19.ael7b_1.3
View patch
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: ntp

Vendor Advisories (1)

redhatCVE-2015-5300Moderate

ntp: MITM attacker can force ntpd to make a step larger than the panic threshold

Oct 21, 2015

References

aix.software.ibm.com / aix/efixes/security/ntp_advisory5.asc
Third Party Advisory
lists.fedoraproject.org / pipermail/package-announce/2015-November/170684.html
Third Party Advisory
lists.fedoraproject.org / pipermail/package-announce/2015-November/170926.html
Third Party Advisory
lists.fedoraproject.org / pipermail/package-announce/2016-February/177507.html
Third Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-04/msg00059.html
Third Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-04/msg00060.html
Third Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-05/msg00020.html
Third Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-05/msg00038.html
Third Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-05/msg00048.html
Third Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-07/msg00026.html
Third Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-08/msg00042.html
Third Party Advisory
lists.opensuse.org / opensuse-updates/2016-05/msg00114.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2015-1930.html
Third Party Advisory
bto.bluecoat.com / security-advisory/sa113
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue Tracking
seclists.org / bugtraq/2016/Feb/164
Mailing ListThird Party Advisory
ics-cert.us-cert.gov / advisories/ICSA-15-356-01
Third Party AdvisoryUS Government Resource
security.netapp.com / advisory/ntap-20171004-0001
support.citrix.com / article/CTX220112
Third Party Advisory
support.ntp.org / bin/view/Main/NtpBug2956
Issue TrackingPatchVendor Advisory
support.ntp.org / bin/view/Main/SecurityNotice
Issue TrackingPatchVendor Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
cs.bu.edu / ~goldbe/NTPattack.html
Third Party Advisory
freebsd.org / security/advisories/FreeBSD-SA-16:02.ntp.asc
Third Party Advisory
ibm.com / support/home/docdisplay
Third Party Advisory
oracle.com / technetwork/topics/security/bulletinjan2016-2867206.html
Third Party Advisory
oracle.com / technetwork/topics/security/linuxbulletinoct2015-2719645.html
Third Party Advisory
debian.org / security/2015/dsa-3388
Third Party Advisory
oracle.com / technetwork/security-advisory/cpujul2016-2881720.html
Third Party Advisory
securityfocus.com / bid/77312
Third Party AdvisoryVDB Entry
securitytracker.com / id/1034670
Third Party AdvisoryVDB Entry
ubuntu.com / usn/USN-2783-1
Third Party Advisory