← Vulnerability feed

Vulnerability record · CVE-2013-5211 · published 2 January 2014

CVE-2013-5211: NTP monlist feature allows traffic amplification denial of service

Opensuse · Opensuse

The monlist feature in ntpd (NTP before 4.2.7p26) responds to forged REQ_MON_GETLIST and REQ_MON_GETLIST_1 requests with a much larger reply, enabling traffic amplification. Attackers spoof a victim's source address so the amplified response floods the victim, causing denial of service. The flaw was exploited in the wild in December 2013 and remains a common reflection/amplification vector.

5.0 CVSS 2.0 Medium EPSS 98% · top 0.1% CWE-20 · Improper input validation
5.0CVSS 2.0 base score
98%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
42References
16 Jun 2026Last modified by NVD

Description

The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service (traffic amplification) via forged (1) REQ_MON_GETLIST or (2) REQ_MON_GETLIST_1 requests, as exploited in the wild in December 2013.

AV:N/AC:L/Au:N/C:N/I:N/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe flaw is trivially exploitable over the network with no authentication, has very high EPSS and documented in-the-wild abuse, though it only causes denial of service.

What it is

The monlist feature in ntpd (NTP before 4.2.7p26) responds to forged REQ_MON_GETLIST and REQ_MON_GETLIST_1 requests with a much larger reply, enabling traffic amplification. Attackers spoof a victim's source address so the amplified response floods the victim, causing denial of service. The flaw was exploited in the wild in December 2013 and remains a common reflection/amplification vector.

Impact

An unauthenticated remote attacker can direct amplified NTP responses at a third-party victim, degrading or denying network and service availability. The attacker gains no code execution or data access; the effect is volumetric DoS.

Attack surface

Reachable over the network via UDP to an exposed NTP service; no authentication or user interaction is required. Any internet-facing ntpd with monlist enabled can be used as an amplifier.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.97549, 99.9th percentile) and the description states it was exploited in the wild in December 2013. Reference tags are advisory and patch links, with no exploit-code tags.

What to do

  • Upgrade ntpd to 4.2.7p26 or later, or apply the vendor patch for your distribution.
  • Disable the monlist/monitoring query feature (e.g., disable monitor or restrict noquery) where it is not needed.
  • Block or rate-limit inbound UDP/123 at the network edge and apply anti-spoofing (BCP 38) to prevent forged source addresses.
  • Restrict NTP query access to trusted clients only and remove internet exposure of NTP servers.
  • Monitor for abnormal outbound NTP response volumes that indicate your server is being used as an amplifier.

Detection

  • Alert on large outbound UDP/123 responses or high NTP response-to-request byte ratios from internal servers.
  • Detect monlist or REQ_MON_GETLIST/REQ_MON_GETLIST_1 query patterns in NTP traffic logs.
  • Monitor for spikes in inbound UDP/123 traffic to a host that did not initiate NTP requests (reflection victim).
  • Inventory internet-facing NTP services and verify monlist is disabled or access-restricted.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://aix.software.ibm.com/aix/efixes/security/ntp_advisory.asc Third Party Advisory
http://bugs.ntp.org/show_bug.cgi?id=1532 Issue Tracking
http://ics-cert.us-cert.gov/advisories/ICSA-14-051-04 Third Party AdvisoryUS Government Resource
http://lists.ntp.org/pipermail/pool/2011-December/005616.html Broken Link
http://lists.opensuse.org/opensuse-updates/2014-09/msg00031.html Third Party Advisory
http://marc.info/?l=bugtraq&m=138971294629419&w=2 Mailing List
http://marc.info/?l=bugtraq&m=144182594518755&w=2 Mailing ListThird Party Advisory
http://openwall.com/lists/oss-security/2013/12/30/6 Mailing List
http://openwall.com/lists/oss-security/2013/12/30/7 Mailing List
http://secunia.com/advisories/59288 Not Applicable
http://secunia.com/advisories/59726 Not Applicable
http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095861 Broken Link
http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095892 Broken Link
http://www.eecis.udel.edu/~ntp/ntp_spool/ntp4/ntp-dev/ntp-dev-4.2.7p26.tar.gz Patch
http://www.kb.cert.org/vuls/id/348126 Third Party AdvisoryUS Government Resource
http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html Third Party Advisory
http://www.securityfocus.com/bid/64692 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1030433 Third Party AdvisoryVDB Entry
http://www.us-cert.gov/ncas/alerts/TA14-013A Third Party AdvisoryUS Government Resource
https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04790232 Third Party Advisory
https://puppet.com/security/cve/puppetlabs-ntp-nov-2015-advisory Broken Link
http://aix.software.ibm.com/aix/efixes/security/ntp_advisory.asc Third Party Advisory
http://bugs.ntp.org/show_bug.cgi?id=1532 Issue Tracking
http://ics-cert.us-cert.gov/advisories/ICSA-14-051-04 Third Party AdvisoryUS Government Resource
http://lists.ntp.org/pipermail/pool/2011-December/005616.html Broken Link
http://lists.opensuse.org/opensuse-updates/2014-09/msg00031.html Third Party Advisory
http://marc.info/?l=bugtraq&m=138971294629419&w=2 Mailing List
http://marc.info/?l=bugtraq&m=144182594518755&w=2 Mailing ListThird Party Advisory
http://openwall.com/lists/oss-security/2013/12/30/6 Mailing List
http://openwall.com/lists/oss-security/2013/12/30/7 Mailing List
http://secunia.com/advisories/59288 Not Applicable
http://secunia.com/advisories/59726 Not Applicable
http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095861 Broken Link
http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095892 Broken Link
http://www.eecis.udel.edu/~ntp/ntp_spool/ntp4/ntp-dev/ntp-dev-4.2.7p26.tar.gz Patch
http://www.kb.cert.org/vuls/id/348126 Third Party AdvisoryUS Government Resource
http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html Third Party Advisory
http://www.securityfocus.com/bid/64692 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1030433 Third Party AdvisoryVDB Entry
http://www.us-cert.gov/ncas/alerts/TA14-013A Third Party AdvisoryUS Government Resource

Track CVE-2013-5211 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-4171Adobe Flash Player unspecified remote code execution flawCVE-2016-4171 is an unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier that allows remote attackers to execute arbitrary code thr…KEVEPSS 20%analysed9.8CVE-2016-4117Adobe Flash Player unspecified vectors allow arbitrary code executionAdobe Flash Player 21.0.0.226 and earlier contains a critical flaw that lets remote attackers execute arbitrary code through unspecified vectors. Ado…KEVEPSS 94%analysed9.8CVE-2016-3427Oracle Java SE JMX Improper Access Control VulnerabilityCVE-2016-3427 is an unspecified vulnerability in Oracle Java SE 6u113, 7u99, 8u77, Java SE Embedded 8u77, and JRockit R28.3.9, reached through vector…KEVEPSS 92%analysed9.8CVE-2015-2590Oracle Java SE Libraries flaw allows remote code executionCVE-2015-2590 is an unspecified vulnerability in the Libraries component of Oracle Java SE 6u95, 7u80, 8u45 and Java SE Embedded 7u75, 8u33. The reco…KEVEPSS 25%analysed9.8CVE-2015-5119Adobe Flash Player ActionScript 3 ByteArray use-after-freeA use-after-free flaw exists in the ByteArray class of the ActionScript 3 implementation in Adobe Flash Player. Crafted Flash content that overrides …KEVEPSS 99%analysed9.8CVE-2015-3113Adobe Flash Player heap buffer overflow allows remote code executionAdobe Flash Player contains a heap-based buffer overflow (CWE-122/CWE-787) reachable through unspecified vectors. It affects Flash Player before 13.0…KEVEPSS 100%analysed9.8CVE-2015-3043Adobe Flash Player memory corruption allows arbitrary code executionAdobe Flash Player contains an out-of-bounds write (CWE-787) that corrupts memory and can lead to arbitrary code execution or a denial of service. Th…KEVEPSS 74%analysed9.8CVE-2015-0313Adobe Flash Player use-after-free allows remote code executionAdobe Flash Player contains a use-after-free (CWE-416) flaw reachable through unspecified vectors. It affects Flash Player before 13.0.0.269 and 14.x…KEVEPSS 95%analysed

Source: NIST National Vulnerability Database (record CVE-2013-5211), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.