CVE-2015-7871 is a critical authentication bypass vulnerability affecting NTP 4.2.x before 4.2.8p4 and 4.3.x before 4.3.77, including products from Debian and NetApp. This flaw, rated 9.8 CRITICAL, allows remote, unauthenticated attackers to bypass authentication via Crypto-NAK packets, leading to high impact on confidentiality, integrity, and availability. While not on the KEV catalog, exploit modules like Metasploit's "NAK to the Future" exist, and it has garnered significant community discussion and media coverage, indicating high awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.2.6, < 4.2.8CPE matchmatch criteria | cpe:2.3:a:ntp:ntp:*:*:*:*:*:*:*:* | ||
>= 4.3.0, < 4.3.77CPE matchmatch criteria | cpe:2.3:a:ntp:ntp:*:*:*:*:*:*:*:* | ||
4.2.5CPE matchmatch criteria | cpe:2.3:a:ntp:ntp:4.2.5:p186:*:*:*:*:*:* | ||
4.2.5CPE matchmatch criteria | cpe:2.3:a:ntp:ntp:4.2.5:p187:*:*:*:*:*:* | ||
4.2.5CPE matchmatch criteria | cpe:2.3:a:ntp:ntp:4.2.5:p188:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.