1.8

CVE-2015-1798

The symmetric-key feature in the receive function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p2 requires a correct MAC only if the MAC field has a nonzero length, which makes it easier for man-in-the-middle attackers to spoof packets by omitting the MAC.

Data is provided by the National Vulnerability Database (NVD)
NtpNtp Version <= 4.2.7p444
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.58% 0.678
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 1.8 3.2 2.9
AV:A/AC:H/Au:N/C:N/I:P/A:N