Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2016-7431

23
FAUCET Score

CVE-2016-7431 is a medium-severity vulnerability affecting NTP before version 4.2.8p9, allowing remote attackers to bypass origin timestamp protection by sending a zero-value origin timestamp. This flaw, a regression of CVE-2015-8138, has a CVSSv3 score of 5.3, indicating a network-based attack with low complexity and potential for limited integrity impact. While there is no known exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered some community discussion and media coverage, though it is not listed on the CISA KEV catalog.

Impacted Technologies

VendorProductVersion(s)CPE
4.2.8CPE matchmatch criteria
cpe:2.3:a:ntp:ntp:4.2.8:p8:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

5.3MEDIUM

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
1.4
CvssVersion
3.0

Exploit Intelligence

EPSS Score
8.71%
Probability of exploitation in next 30 days
EPSS Percentile
94.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0871 is in the 93rd percentile among its peer group of 23,701 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2016-7431Moderate

ntp: Zero Origin timestamp regression

Nov 21, 2016

References

lists.opensuse.org / opensuse-updates/2016-12/msg00153.html
nwtime.org / ntp428p9_release
Release NotesVendor Advisory
packetstormsecurity.com / files/140240/FreeBSD-Security-Advisory-FreeBSD-SA-16.39.ntp.html
bto.bluecoat.com / security-advisory/sa139
cert-portal.siemens.com / productcert/pdf/ssa-211752.pdf
h20566.www2.hpe.com / hpsc/doc/public/display
security.freebsd.org / advisories/FreeBSD-SA-16:39.ntp.asc
support.hpe.com / hpsc/doc/public/display
support.hpe.com / hpsc/doc/public/display
support.hpe.com / hpsc/doc/public/display
support.hpe.com / hpsc/doc/public/display
support.ntp.org / bin/view/Main/NtpBug3102
Issue TrackingMitigationVendor Advisory
support.ntp.org / bin/view/Main/SecurityNotice
Vendor Advisory
us-cert.cisa.gov / ics/advisories/icsa-21-159-11
broadcom.com / support/fibre-channel-networking/security-advisories/brocade-security-advisory-2017-223
kb.cert.org / vuls/id/633847
Third Party AdvisoryUS Government Resource
huawei.com / en/psirt/security-advisories/huawei-sa-20171129-01-ntpd-en
oracle.com / technetwork/security-advisory/cpuoct2017-3236626.html
securityfocus.com / archive/1/539955/100/0/threaded
securityfocus.com / archive/1/540254/100/0/threaded
securityfocus.com / archive/1/archive/1/539955/100/0/threaded
securityfocus.com / archive/1/archive/1/540254/100/0/threaded
securityfocus.com / bid/94454
securitytracker.com / id/1037354
ubuntu.com / usn/USN-3349-1