CVE-2015-5300 describes a vulnerability in NTP versions prior to 4.2.8p5, specifically within the panic_gate check, affecting products from vendors like Canonical, Debian, and Red Hat. This flaw allows remote attackers to manipulate system time, either by setting an arbitrary time when NTP is started with the -g option, or by altering the time by up to 900 seconds through responding to trusted requests, leading to a denial of service due to an abort and restart. With a CVSS score of 7.5 (High), the vulnerability is network-exploitable with low attack complexity, resulting in a high impact on availability. While there is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB) is unavailable, and community discussion is minimal, though it has received some media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
21CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:* | ||
22CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:* | ||
11CPE matchmatch criteria | cpe:2.3:a:suse:linux_enterprise_debuginfo:11:sp2:*:*:*:*:*:* | ||
11CPE matchmatch criteria | cpe:2.3:a:suse:linux_enterprise_debuginfo:11:sp3:*:*:*:*:*:* | ||
11CPE matchmatch criteria | cpe:2.3:a:suse:linux_enterprise_debuginfo:11:sp4:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.