Vulnerability record · CVE-2015-7871 · published 7 August 2017
CVE-2015-7871: ntpd Crypto-NAK packets bypass authentication
Ntp · Ntp
ntpd in NTP 4.2.x before 4.2.8p4 and 4.3.x before 4.3.77 mishandles Crypto-NAK packets, allowing remote attackers to bypass authentication. Because NTP authentication is meant to protect time synchronization, a bypass undermines trust in the protocol and can enable spoofed or manipulated time data. The record does not detail the exact internal mechanism beyond the authentication bypass.
Description
Crypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to bypass authentication.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCritical CVSS (9.8) authentication bypass with very high EPSS, but no KEV listing or documented in-the-wild exploitation in this record.
What it is
ntpd in NTP 4.2.x before 4.2.8p4 and 4.3.x before 4.3.77 mishandles Crypto-NAK packets, allowing remote attackers to bypass authentication. Because NTP authentication is meant to protect time synchronization, a bypass undermines trust in the protocol and can enable spoofed or manipulated time data. The record does not detail the exact internal mechanism beyond the authentication bypass.
Impact
An unauthenticated remote attacker can bypass NTP authentication, potentially allowing forged or spoofed time responses that clients may accept. This can corrupt time synchronization and, depending on downstream reliance on NTP, affect logging, certificate validation and other time-dependent controls.
Attack surface
Reachable over the network via NTP packets (CVSS vector AV:N/AC:L/PR:N/UI:N), so no authentication or user interaction is required. Any host running an affected ntpd version and reachable on its NTP port is exposed.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented, but EPSS is very high (0.81762, 99.6th percentile), indicating elevated likelihood of exploitation activity. References are vendor and third-party advisories only; no public exploit tag is present in the record.
What to do
- Upgrade ntpd to 4.2.8p4 or later (or 4.3.77 or later for the 4.3.x branch), or apply the vendor patch for your distribution.
- Where patching is delayed, restrict NTP (UDP 123) access to trusted time sources and block external NTP traffic at the perimeter.
- Enable and verify NTP authentication (symmetric keys or autokey) on clients and servers, and monitor for authentication failures.
- Check downstream products listed as affected (Debian, NetApp ONTAP/OnCommand, HPE, Gentoo, Siemens) and apply their respective advisories.
- Reduce reliance on unauthenticated NTP by using multiple trusted time sources and monitoring for time drift.
Detection
- Monitor NTP logs and packet captures for anomalous Crypto-NAK packets or unexpected authentication failures.
- Alert on NTP server or client time changes that deviate from expected drift baselines.
- Track ntpd versions across the estate and flag hosts still running versions before 4.2.8p4 or 4.3.77.
- Watch for unusual inbound UDP 123 traffic from untrusted external sources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-7871 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-7871), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.