CVE-2015-7974

Source
https://cve.org/CVERecord?id=CVE-2015-7974
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2015-7974.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2015-7974
Downstream
Related
Withdrawn
2026-01-27T04:15:10.250656Z
Published
2016-01-26T19:59:00Z
Modified
2026-01-27T04:15:10.250656Z
Severity
  • 7.7 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

NTP 4.x before 4.2.8p6 and 4.3.x before 4.3.90 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via an arbitrary trusted key, aka a "skeleton key."

References

Affected packages