CVE-2016-1551

ntpd in NTP 4.2.8p3 and NTPsec a5fb34b9cc89b92a8fef2f459004865c93bb7f92 relies on the underlying operating system to protect it from requests that impersonate reference clocks. Because reference clocks are treated like other peers and stored in the same structure, any packet with a source ip address of a reference clock (127.127.1.1 for example) that reaches the receive() function will match that reference clock's peer record and will be treated as a trusted peer. Any system that lacks the typical martian packet filtering which would block these packets is in danger of having its time controlled by an attacker.

Published: 2017-01-27 Last update: 2026-05-13 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2016-1551 is rated Moderate Risk (41.7/100): CVSS Low severity, with medium exploitation likelihood (EPSS 0.98%). Mandatory action: Review affected assets and schedule remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2016-1551

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2025-12-28 0.73% 0.98% +0.24%
2 2025-12-27 0.98% 0.73% -0.24%
3 2025-12-20 0.98%

Full EPSS history (11 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2016-1551

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
3.7 3.0 LOW
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:H)
Even with access, the exploit needs extra luck, timing, or a fussy environment to actually work.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:N)
Doesn’t really leak secrets in a meaningful way.
Integrity (I:L)
Attackers could change some data, but it’s limited—not everything goes.
Availability (A:N)
Service keeps running; no real outage angle.
2.2 1.4 [email protected]
2.6 2.0 LOW
AV:N/AC:H/Au:N/C:N/I:P/A:N Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:H)
Exploitation requires uncommon or highly specific conditions.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:N)
No confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:N)
No availability impact.
4.9 2.9 [email protected]

Weakness enumeration for CVE-2016-1551

OS Trackers for CVE-2016-1551

vendor priority summary link
debian unimportant CVE-2016-1551 unimportant priority: Debian including 1 source packages (ntp), 1 status rows across 1 suites (bullseye): resolved 1. https://security-tracker.debian.org/tracker/CVE-2016-1551
gentoo normal CVE-2016-1551: 1 GLSA(s) (201607-15), 1 atom(s) (net-misc/ntp); latest impact normal. https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2016-1551
redhat low https://access.redhat.com/security/cve/CVE-2016-1551
suse low CVE-2016-1551 severity low: SUSE including 22 source package names (ntp-4.2.8p10-63.3, ntp-4.2.8p11-2.12, …), 80 product×package rows across 54 product lines (Image SLES12-SP5-Azure-BYOS, Image SLES12-SP5-Azure-Basic-On-Demand, … (54 product lines)): Fixed 80. https://www.suse.com/security/cve/CVE-2016-1551/
ubuntu negligible CVE-2016-1551 negligible priority: Ubuntu including 1 source packages (ntp), 5 status rows across 5 suites (precise, trusty, upstream, wily, xenial): not-affected 4, released 1. https://ubuntu.com/security/CVE-2016-1551

Affected software / configurations for CVE-2016-1551

Vendor Product Version Raw CPE
ntp ntp 4.2.8 cpe:2.3:a:ntp:ntp:4.2.8:p3:*:*:*:*:*:*
ntpsec ntpsec a5fb34b9cc89b92a8fef2f459004865c93bb7f92 cpe:2.3:a:ntpsec:ntpsec:a5fb34b9cc89b92a8fef2f459004865c93bb7f92:*:*:*:*:*:*:*

References for CVE-2016-1551

cvelogic Threat Intelligence