Free and open-source vulnerability scanner

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

NTP Monlist Feature Enabled

Information

Severity

Severity

Medium

Family

Family

Denial of Service

CVSSv2 Base

CVSSv2 Base

5.0

CVSSv2 Vector

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:P

Solution Type

Solution Type

Vendor Patch

Created

Created

10 years ago

Modified

Modified

5 years ago

Summary

NTP is prone to a remote denial-of-service vulnerability because it fails to properly handle certain incoming network packets.

Insight

Insight

The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service (traffic amplification) via forged (1) REQ_MON_GETLIST or (2) REQ_MON_GETLIST_1 requests, as exploited in the wild in December 2013.

Affected Software

Affected Software

NTP before 4.2.7p26

Detection Method

Detection Method

Send a NTP monlist request and check the response.

Solution

Solution

Update to NTP 4.2.7p26 or newer or set 'disable monitor' in ntp.conf.

Common Vulnerabilities and Exposures (CVE)