CVE-2015-7702 is a denial-of-service vulnerability affecting NTP 4.2.x before 4.2.8p4 and 4.3.x before 4.3.77, stemming from an incomplete fix for a previous vulnerability. It allows remote attackers to crash the ntpd service, impacting products from vendors like Debian, NetApp, Oracle, and Red Hat. With a CVSS score of 6.5 (Medium), it can be exploited remotely with low complexity and no user interaction, leading to high availability impact. Currently, there is no known public exploit code (Metasploit, Nuclei, ExploitDB), it is not listed on the CISA KEV catalog, and it has received minimal community discussion or media coverage, suggesting low active exploitation or public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.2.0, < 4.2.8CPE matchmatch criteria | cpe:2.3:a:ntp:ntp:*:*:*:*:*:*:*:* | ||
>= 4.3.0, < 4.3.77CPE matchmatch criteria | cpe:2.3:a:ntp:ntp:*:*:*:*:*:*:*:* | ||
4.2.8CPE matchmatch criteria | cpe:2.3:a:ntp:ntp:4.2.8:-:*:*:*:*:*:* | ||
4.2.8CPE matchmatch criteria | cpe:2.3:a:ntp:ntp:4.2.8:p1:*:*:*:*:*:* | ||
4.2.8CPE matchmatch criteria | cpe:2.3:a:ntp:ntp:4.2.8:p1-beta1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.