ntp: DoS in monlist feature in ntpd
Published Jan 2, 2014
5.0
MEDIUMCVSS 2.0
EPSS 97.55%
Description
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service (traffic amplification) via forged (1) REQ_MON_GETLIST or (2) REQ_MON_GETLIST_1 requests, as exploited in the wild in December 2013.
Affected products
No data.
Configuration 2
- < 4.2.7
- 4.2.7
- 4.2.7
- 4.2.7
- 4.2.7
- 4.2.7
- 4.2.7
- 4.2.7
- 4.2.7
- 4.2.7
- 4.2.7
- 4.2.7
- 4.2.7
- 4.2.7
- 4.2.7
- 4.2.7
- 4.2.7
- 4.2.7
- 4.2.7
- 4.2.7
- 4.2.7
- 4.2.7
- 4.2.7
- 4.2.7
- 4.2.7
- 4.2.7
- 4.2.7
- 4.2.7
No data.
Red Hat Enterprise Linux 5
ntp
Will not fix
Red Hat Enterprise Linux 6
ntp
Will not fix
Red Hat Enterprise Linux 7
ntp
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | ntp | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | ntp | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | ntp | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue does not affect the default configuration of ntp packages shipped with Red Hat Enterprise Linux, which does not allow remote ntpd control queries. User changing ntpd access control configuration should consider reviewing additional information provided via https://bugzilla.redhat.com/show_bug.cgi?id=1047854#c27 to avoid exposing their systems to this traffic amplification issue.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (22 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 97.55% (0.97549) | 99.90th | v5 (v2026.06.15) |
| Jun 15, 2026 | 98.13% (0.98134) | 99.91th | v5 (v2026.06.15) |
| Sep 24, 2025 | 91.78% (0.91783) | 99.67th | v4 (v2025.03.14) |
| Aug 22, 2025 | 90.75% (0.90751) | 99.60th | v4 (v2025.03.14) |
| Mar 30, 2025 | 92.48% (0.92485) | 99.73th | v4 (v2025.03.14) |
| Mar 29, 2025 | 90.79% (0.90787) | 99.56th | v4 (v2025.03.14) |
| Mar 17, 2025 | 92.48% (0.92485) | 99.73th | v4 (v2025.03.14) |
| Jan 26, 2025 | 92.57% (0.92568) | 99.25th | v3 (v2023.03.01) |
| Dec 17, 2024 | 91.24% (0.91242) | 99.13th | v3 (v2023.03.01) |
| Dec 12, 2024 | 96.26% (0.96257) | 99.60th | v3 (v2023.03.01) |
| Jul 20, 2024 | 96.43% (0.96433) | 99.60th | v3 (v2023.03.01) |
| Apr 7, 2024 | 96.70% (0.96703) | 99.64th | v3 (v2023.03.01) |
| Jan 1, 2024 | 96.63% (0.96626) | 99.54th | v3 (v2023.03.01) |
| Nov 15, 2023 | 96.65% (0.96649) | 99.53th | v3 (v2023.03.01) |
| Nov 2, 2023 | 96.62% (0.96617) | 99.50th | v3 (v2023.03.01) |
| Sep 29, 2023 | 97.42% (0.97421) | 99.91th | v3 (v2023.03.01) |
| Jun 29, 2023 | 97.39% (0.97386) | 99.86th | v3 (v2023.03.01) |
| May 9, 2023 | 97.40% (0.97402) | 99.86th | v3 (v2023.03.01) |
| Mar 7, 2023 | 97.42% (0.97424) | 99.86th | v3 (v2023.03.01) |
| Mar 6, 2023 | 88.12% (0.88124) | 99.78th | v2 (v2022.01.01) |
| Jun 16, 2022 | 88.12% (0.88124) | 99.77th | v2 (v2022.01.01) |
| Feb 4, 2022 | 88.95% (0.88952) | 99.78th | v2 (v2022.01.01) |
References (26)
- http://aix.software.ibm.com/aix/efixes/security/ntp_advisory.asc x_refsource_CONFIRMThird Party Advisory
- http://bugs.ntp.org/show_bug.cgi?id=1532 x_refsource_CONFIRMIssue Tracking
- http://ics-cert.us-cert.gov/advisories/ICSA-14-051-04 x_refsource_MISCThird Party AdvisoryUS Government Resource
- http://lists.ntp.org/pipermail/pool/2011-December/005616.html mailing-listx_refsource_MLISTBroken Link
- http://lists.opensuse.org/opensuse-updates/2014-09/msg00031.html vendor-advisoryx_refsource_SUSEThird Party Advisory
- http://marc.info/?l=bugtraq&m=138971294629419&w=2 vendor-advisoryx_refsource_HPMailing List
- http://marc.info/?l=bugtraq&m=144182594518755&w=2 vendor-advisoryx_refsource_HPMailing ListThird Party Advisory
- http://openwall.com/lists/oss-security/2013/12/30/6 mailing-listx_refsource_MLISTMailing List
- http://openwall.com/lists/oss-security/2013/12/30/7 mailing-listx_refsource_MLISTMailing List
- http://secunia.com/advisories/59288 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59726 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095861 x_refsource_CONFIRMBroken Link
- http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095892 x_refsource_CONFIRMBroken Link
- http://www.eecis.udel.edu/~ntp/ntp_spool/ntp4/ntp-dev/ntp-dev-4.2.7p26.tar.gz x_refsource_CONFIRMPatch
- http://www.kb.cert.org/vuls/id/348126 third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html x_refsource_CONFIRMThird Party Advisory
- http://www.securityfocus.com/bid/64692 vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1030433 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- http://www.us-cert.gov/ncas/alerts/TA14-013A third-party-advisoryx_refsource_CERTThird Party AdvisoryUS Government Resource
- https://access.redhat.com/security/cve/CVE-2013-5211 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1047854 Issue Tracking
- https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04790232 x_refsource_CONFIRMThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2013-5211
- https://puppet.com/security/cve/puppetlabs-ntp-nov-2015-advisory x_refsource_CONFIRMBroken Link
- https://www.cve.org/CVERecord?id=CVE-2013-5211
- https://www.us-cert.gov/ncas/alerts/TA14-013A
Change history (0)
No recorded changes yet.