CVE-2016-1551 describes a vulnerability in ntpd (NTP 4.2.8p3) and NTPsec (a5fb34b9cc89b92a8fef2f459004865c93bb7f92) where the NTP daemon fails to adequately protect against spoofed reference clock requests, treating them as trusted peers. This allows an attacker to manipulate a system's time if the underlying operating system lacks proper martian packet filtering. The vulnerability has a low CVSS score of 3.7, indicating a network attack vector with high attack complexity and a low impact on integrity. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion, with only one mention and one media article identified.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.2.8CPE matchmatch criteria | cpe:2.3:a:ntp:ntp:4.2.8:p3:*:*:*:*:*:* | ||
a5fb34b9cc89b92a8fef2f459004865c93bb7f92CPE matchmatch criteria | cpe:2.3:a:ntpsec:ntpsec:a5fb34b9cc89b92a8fef2f459004865c93bb7f92:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.