Vulnerability Details CVE-2015-7855
The decodenetnum function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (assertion failure) via a 6 or mode 7 packet containing a long data value.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.484
EPSS Ranking 97.6%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 4.0
Products affected by CVE-2015-7855
-
cpe:2.3:a:netapp:oncommand_balance:-
-
cpe:2.3:a:netapp:oncommand_performance_manager:-
-
cpe:2.3:a:netapp:oncommand_unified_manager:-
-
-
-
-
-
-
-
Ntp
»
Ntp
»
Version: 4.2.7p444
cpe:2.3:a:ntp:ntp:4.2.7p444
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
cpe:2.3:h:siemens:tim_4r-ie:-
-
cpe:2.3:h:siemens:tim_4r-ie_dnp3:-
-
cpe:2.3:o:debian:debian_linux:7.0
-
cpe:2.3:o:debian:debian_linux:8.0
-
cpe:2.3:o:debian:debian_linux:9.0
-
cpe:2.3:o:netapp:clustered_data_ontap:-
-
cpe:2.3:o:netapp:data_ontap:-
-
cpe:2.3:o:siemens:tim_4r-ie_dnp3_firmware:-
-
cpe:2.3:o:siemens:tim_4r-ie_dnp3_firmware:3.3
-
cpe:2.3:o:siemens:tim_4r-ie_firmware:-
-
cpe:2.3:o:siemens:tim_4r-ie_firmware:3.3