Vulnerability record · CVE-2013-5211 · published 2 January 2014
CVE-2013-5211: NTP monlist feature allows traffic amplification denial of service
Opensuse · Opensuse
The monlist feature in ntpd (NTP before 4.2.7p26) responds to forged REQ_MON_GETLIST and REQ_MON_GETLIST_1 requests with a much larger reply, enabling traffic amplification. Attackers spoof a victim's source address so the amplified response floods the victim, causing denial of service. The flaw was exploited in the wild in December 2013 and remains a common reflection/amplification vector.
Description
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service (traffic amplification) via forged (1) REQ_MON_GETLIST or (2) REQ_MON_GETLIST_1 requests, as exploited in the wild in December 2013.
AV:N/AC:L/Au:N/C:N/I:N/A:P
Automated analysis
high priorityThe flaw is trivially exploitable over the network with no authentication, has very high EPSS and documented in-the-wild abuse, though it only causes denial of service.
What it is
The monlist feature in ntpd (NTP before 4.2.7p26) responds to forged REQ_MON_GETLIST and REQ_MON_GETLIST_1 requests with a much larger reply, enabling traffic amplification. Attackers spoof a victim's source address so the amplified response floods the victim, causing denial of service. The flaw was exploited in the wild in December 2013 and remains a common reflection/amplification vector.
Impact
An unauthenticated remote attacker can direct amplified NTP responses at a third-party victim, degrading or denying network and service availability. The attacker gains no code execution or data access; the effect is volumetric DoS.
Attack surface
Reachable over the network via UDP to an exposed NTP service; no authentication or user interaction is required. Any internet-facing ntpd with monlist enabled can be used as an amplifier.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.97549, 99.9th percentile) and the description states it was exploited in the wild in December 2013. Reference tags are advisory and patch links, with no exploit-code tags.
What to do
- Upgrade ntpd to 4.2.7p26 or later, or apply the vendor patch for your distribution.
- Disable the monlist/monitoring query feature (e.g., disable monitor or restrict noquery) where it is not needed.
- Block or rate-limit inbound UDP/123 at the network edge and apply anti-spoofing (BCP 38) to prevent forged source addresses.
- Restrict NTP query access to trusted clients only and remove internet exposure of NTP servers.
- Monitor for abnormal outbound NTP response volumes that indicate your server is being used as an amplifier.
Detection
- Alert on large outbound UDP/123 responses or high NTP response-to-request byte ratios from internal servers.
- Detect monlist or REQ_MON_GETLIST/REQ_MON_GETLIST_1 query patterns in NTP traffic logs.
- Monitor for spikes in inbound UDP/123 traffic to a host that did not initiate NTP requests (reflection victim).
- Inventory internet-facing NTP services and verify monlist is disabled or access-restricted.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-5211 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-5211), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.