SynopsisThe remote device is missing a vendor-supplied security patch.
DescriptionSome kernels do not offer protection for ::1 source addresses on IPv6 interfaces. Since NTP's access control mechanism is based on source address and localhost addresses generally have no restrictions, an attacker may be able to send malicious control and configuration packets by spoofing ::1 addresses from the outside. (CVE-2014-9751)
Note: The candidate number originally referenced in this article, CVE-2014-9298, was rejected because it was associated with two different issues.
SolutionUpgrade to one of the non-vulnerable versions listed in the F5 Solution K16393.