NTP.Monlist.Command.DoS

description-logoDescription

This indicates an attack attempt against a Denial of Service vulnerability in NTP service.
The vulnerability is due to an error when the vulnerable software handles a maliciously crafted request. A remote attacker may be able to exploit this to cause a denial of service condition on the affected system.

affected-products-logoAffected Products

NTP before 4.2.7p26

Impact logoImpact

Denial of Service: Remote attackers can crash vulnerable systems.

recomended-action-logoRecommended Actions

Upgrade to the NTP version 4.2.7, which removes the monlist command entirely. Or you can start the NTP daemon with noquery enabled in the NTP conf file. This will disable access to mode 6 and 7 query packetts.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2019-04-17 14.596 Sig Added
2019-04-03 14.585 Sig Added