CVE-2015-1853
Last modified
CVE-2015-1853 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. chrony before 1.31.1 does not properly protect state variables in authenticated symmetric NTP associations, which allows remote attackers with knowledge of NTP peering to cause a denial of service (inability to synchronize) via random timestamps in crafted NTP data packets.. EPSS estimates a 1.70% chance of exploitation in the next 30 days.
Description
chrony before 1.31.1 does not properly protect state variables in authenticated symmetric NTP associations, which allows remote attackers with knowledge of NTP peering to cause a denial of service (inability to synchronize) via random timestamps in crafted NTP data packets.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tuxfamily | Chrony | < 1.31.1 |
References
- http://chrony.tuxfamily.org/News.htmlRelease Notes, Vendor Advisory
- https://security.gentoo.org/glsa/201507-01Third Party Advisory
- http://chrony.tuxfamily.org/News.htmlRelease Notes, Vendor Advisory
- https://security.gentoo.org/glsa/201507-01Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-1853?
How severe is CVE-2015-1853?
How do I fix CVE-2015-1853?
Are you affected by CVE-2015-1853?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
