CVE-2013-5211

The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service (traffic amplification)...

Basic Information

CVE State
PUBLISHED
Reserved Date
August 15, 2013
Published Date
January 02, 2014
Last Updated
August 06, 2024
Vendor
NTP
Product
NTP
Description
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service (traffic amplification) via forged (1) REQ_MON_GETLIST or (2) REQ_MON_GETLIST_1 requests, as exploited in the wild in December 2013.

CVSS Scores

CVSS v2.0

5.0

Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Exploit Status

Exploited in the Wild
Yes (2014-01-02 11:00:00 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CVE 2014-01-02 11:00:00 UTC

Potential Proof of Concepts

Warning: These PoCs have not been tested and could contain malware. Use at your own risk.

requiempentest/NTP_CVE-2013-5211

Type: github • Created: 2024-10-16 09:45:53 UTC • Stars: 0

Exploit and check CVE-2013-5211

0xhav0c/CVE-2013-5211

Type: github • Created: 2023-05-03 17:20:51 UTC • Stars: 3

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel