NVD
- Id
- 24038
- Name
- CVE-2015-1799
- Description
- The symmetric-key feature in the receive function in ntp_proto.c in ntpd in NTP 3.x and 4.x before 4.2.8p2 performs state-variable updates upon receiving certain invalid packets, which makes it easier for man-in-the-middle attackers to cause a denial of service (synchronization loss) by spoofing the source IP address of a peer.
- Reject
- CVSS Version
- 2
- CVSS Score
- 4.3
- Severity
- Medium
- CVSS Base Score
- 4.3
- CVSS Impact Subscore
- 4.9
- CVSS Exploit Subscore
- 5.5
- CVSS Vector
- (AV:A/AC:M/Au:N/C:N/I:P/A:P)
- Pub Date
- 2017-01-19
- Published
- 2015-04-08
- Modified Date
- 2016-10-24
- Seq
- 2015-1799