Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2015-7705

36
FAUCET Score

CVE-2015-7705 describes a critical vulnerability in NTP 4.x versions prior to 4.2.8p4 and 4.3.x prior to 4.3.77, affecting products from vendors like Citrix, NetApp, NTP, and Siemens. This flaw in the rate limiting feature allows remote attackers to cause significant impact through a high volume of crafted requests. With a CVSS score of 9.8 (Critical), it is easily exploitable over the network with low attack complexity, potentially leading to high confidentiality, integrity, and availability impacts. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered community discussion and media coverage, indicating awareness of its severity.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.2.0, < 4.2.8CPE matchmatch criteria
cpe:2.3:a:ntp:ntp:*:*:*:*:*:*:*:*
>= 4.3.0, < 4.3.77CPE matchmatch criteria
cpe:2.3:a:ntp:ntp:*:*:*:*:*:*:*:*
4.2.8CPE matchmatch criteria
cpe:2.3:a:ntp:ntp:4.2.8:-:*:*:*:*:*:*
4.2.8CPE matchmatch criteria
cpe:2.3:a:ntp:ntp:4.2.8:p1:*:*:*:*:*:*
4.2.8CPE matchmatch criteria
cpe:2.3:a:ntp:ntp:4.2.8:p1-beta1:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
12.35%
Probability of exploitation in next 30 days
EPSS Percentile
95.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.1235 is in the 92nd percentile among its peer group of 36,835 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (3)

redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: ntp
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: ntp
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: ntp

Vendor Advisories (1)

redhatCVE-2015-7705Moderate

ntp: denial of service by trigerring rate limiting on NTP server

Oct 21, 2015

References

lists.opensuse.org / opensuse-security-announce/2016-05/msg00020.html
lists.opensuse.org / opensuse-security-announce/2016-05/msg00034.html
lists.opensuse.org / opensuse-security-announce/2016-05/msg00037.html
lists.opensuse.org / opensuse-security-announce/2016-05/msg00048.html
lists.opensuse.org / opensuse-security-announce/2016-05/msg00052.html
lists.opensuse.org / opensuse-security-announce/2016-06/msg00001.html
lists.opensuse.org / opensuse-security-announce/2016-06/msg00020.html
lists.opensuse.org / opensuse-security-announce/2016-07/msg00026.html
lists.opensuse.org / opensuse-security-announce/2016-08/msg00042.html
lists.opensuse.org / opensuse-updates/2015-11/msg00093.html
lists.opensuse.org / opensuse-updates/2016-05/msg00114.html
packetstormsecurity.com / files/134137/Slackware-Security-Advisory-ntp-Updates.html
bto.bluecoat.com / security-advisory/sa103
bugzilla.redhat.com / show_bug.cgi
Issue TrackingThird Party AdvisoryVDB Entry
cert-portal.siemens.com / productcert/pdf/ssa-211752.pdf
cert-portal.siemens.com / productcert/pdf/ssa-497656.pdf
Third Party Advisory
eprint.iacr.org / 2015/1020.pdf
Technical Description
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
Third Party AdvisoryVDB Entry
security.gentoo.org / glsa/201607-15
Third Party AdvisoryVDB Entry
security.netapp.com / advisory/ntap-20171004-0001
Third Party Advisory
support.citrix.com / article/CTX220112
Third Party Advisory
support.ntp.org / bin/view/Main/NtpBug2901
Vendor Advisory
support.ntp.org / bin/view/Main/SecurityNotice
Release NotesVendor Advisory
us-cert.cisa.gov / ics/advisories/icsa-21-103-11
Third Party AdvisoryUS Government Resource
us-cert.cisa.gov / ics/advisories/icsa-21-159-11
arista.com / en/support/advisories-notices/security-advisories/1212-security-advisory-0016
cs.bu.edu / ~goldbe/NTPattack.html
Not Applicable
kb.cert.org / vuls/id/718152
Third Party AdvisoryUS Government Resource
tools.cisco.com / security/center/content/CiscoSecurityAdvisory/cisco-sa-20151021-ntp
securityfocus.com / archive/1/536737/100/0/threaded
securityfocus.com / archive/1/536796/100/0/threaded
securityfocus.com / archive/1/archive/1/536737/100/100/threaded
securityfocus.com / archive/1/archive/1/536796/100/100/threaded
securityfocus.com / bid/77284
Third Party AdvisoryVDB Entry
securitytracker.com / id/1033951
Third Party AdvisoryVDB Entry
ubuntu.com / usn/USN-2783-1