Vulnerability Details CVE-2015-7974
NTP 4.x before 4.2.8p6 and 4.3.x before 4.3.90 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via an arbitrary trusted key, aka a "skeleton key."
Exploit prediction scoring system (EPSS) score
EPSS Score 0.042
EPSS Ranking 88.1%
CVSS Severity
CVSS v3 Score 7.7
CVSS v2 Score 4.0
Products affected by CVE-2015-7974
-
cpe:2.3:a:netapp:clustered_data_ontap:-
-
cpe:2.3:a:netapp:oncommand_balance:-
-
-
-
-
-
-
-
Ntp
»
Ntp
»
Version: 4.2.7p444
cpe:2.3:a:ntp:ntp:4.2.7p444
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
cpe:2.3:h:siemens:tim_4r-ie:-
-
cpe:2.3:h:siemens:tim_4r-ie_dnp3:-
-
cpe:2.3:o:debian:debian_linux:8.0
-
cpe:2.3:o:debian:debian_linux:9.0
-
cpe:2.3:o:siemens:tim_4r-ie_dnp3_firmware:-
-
cpe:2.3:o:siemens:tim_4r-ie_dnp3_firmware:3.3
-
cpe:2.3:o:siemens:tim_4r-ie_firmware:-
-
cpe:2.3:o:siemens:tim_4r-ie_firmware:3.3