CVE-2016-1547

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

An off-path attacker can cause a preemptible client association to be demobilized in NTP 4.2.8p4 and earlier and NTPSec a5fb34b9cc89b92a8fef2f459004865c93bb7f92 by sending a crypto NAK packet to a victim client with a spoofed source address of an existing associated peer. This is true even if authentication is enabled.

References

http://www.talosintelligence.com/reports/TALOS-2016-0081/

http://www.securityfocus.com/bid/88276

http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html

http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html

https://security.gentoo.org/glsa/201607-15

http://www.securitytracker.com/id/1035705

http://www.debian.org/security/2016/dsa-3629

https://security.netapp.com/advisory/ntap-20171004-0002/

https://security.FreeBSD.org/advisories/FreeBSD-SA-16:16.ntp.asc

https://access.redhat.com/errata/RHSA-2016:1141

http://rhn.redhat.com/errata/RHSA-2016-1552.html

https://cert-portal.siemens.com/productcert/pdf/ssa-497656.pdf

https://us-cert.cisa.gov/ics/advisories/icsa-21-103-11

https://cert-portal.siemens.com/productcert/pdf/ssa-211752.pdf

Details

Source: MITRE

Published: 2017-01-06

Updated: 2021-06-08

Type: CWE-20

Risk Information

CVSS v2

Base Score: 5

Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Impact Score: 2.9

Exploitability Score: 10

Severity: MEDIUM

CVSS v3

Base Score: 5.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Impact Score: 1.4

Exploitability Score: 3.9

Severity: MEDIUM

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:ntp:ntp:*:p4:*:*:*:*:*:* versions up to 4.2.8 (inclusive)

Tenable Plugins

View all (30 total)

IDNameProductFamilySeverity
125008EulerOS Virtualization 3.0.1.0 : ntp (EulerOS-SA-2019-1555)NessusHuawei Local Security Checks
high
107061Arista Networks EOS Multiple Vulnerabilities (SA0019)NessusMisc.
high
104204OracleVM 3.3 / 3.4 : ntp (OVMSA-2017-0165)NessusOracleVM Local Security Checks
high
104100Juniper Junos Space < 17.1R1 Multiple Vulnerabilities (JSA10826)NessusJunos Local Security Checks
high
99183AIX NTP v4 Advisory : ntp_advisory7.asc (IV87278) (IV87279)NessusAIX Local Security Checks
high
95961F5 Networks BIG-IP : NTP vulnerability (K11251130)NessusF5 Networks Local Security Checks
high
93896Ubuntu 12.04 LTS / 14.04 LTS / 16.04 LTS : ntp vulnerabilities (USN-3096-1)NessusUbuntu Local Security Checks
high
93352AIX 7.2 TL 0 : ntp (IV87939) (deprecated)NessusAIX Local Security Checks
high
93351AIX 7.1 TL 3 : ntp (IV87615) (deprecated)NessusAIX Local Security Checks
high
93350AIX 5.3 TL 12 : ntp (IV87614) (deprecated)NessusAIX Local Security Checks
high
93349AIX 7.1 TL 4 : ntp (IV87420) (deprecated)NessusAIX Local Security Checks
high
93348AIX 6.1 TL 9 : ntp (IV87419) (deprecated)NessusAIX Local Security Checks
high
93186SUSE SLES10 Security Update : ntp (SUSE-SU-2016:1912-1)NessusSuSE Local Security Checks
critical
92718RHEL 6 : ntp (RHSA-2016:1552)NessusRed Hat Local Security Checks
high
92571Debian DSA-3629-1 : ntp - security updateNessusDebian Local Security Checks
high
92546Debian DLA-559-1 : ntp security updateNessusDebian Local Security Checks
high
92485GLSA-201607-15 : NTP: Multiple vulnerabilitiesNessusGentoo Local Security Checks
critical
91663SUSE SLED12 / SLES12 Security Update : ntp (SUSE-SU-2016:1568-1)NessusSuSE Local Security Checks
critical
91644Scientific Linux Security Update : ntp on SL6.x, SL7.x i386/x86_64 (20160531)NessusScientific Linux Local Security Checks
high
91420RHEL 6 / 7 : ntp (RHSA-2016:1141)NessusRed Hat Local Security Checks
high
91419OracleVM 3.3 / 3.4 : ntp (OVMSA-2016-0082)NessusOracleVM Local Security Checks
high
91418Oracle Linux 6 / 7 : ntp (ELSA-2016-1141)NessusOracle Linux Local Security Checks
high
91403openSUSE Security Update : ntp (openSUSE-2016-649)NessusSuSE Local Security Checks
critical
91394CentOS 6 / 7 : ntp (CESA-2016:1141)NessusCentOS Local Security Checks
high
91269openSUSE Security Update : ntp (openSUSE-2016-599)NessusSuSE Local Security Checks
critical
91159SUSE SLED12 / SLES12 Security Update : ntp (SUSE-SU-2016:1291-1)NessusSuSE Local Security Checks
critical
91120SUSE SLES11 Security Update : ntp (SUSE-SU-2016:1278-1)NessusSuSE Local Security Checks
critical
90923Network Time Protocol Daemon (ntpd) 3.x / 4.x < 4.2.8p7 Multiple VulnerabilitiesNessusMisc.
critical
90800Slackware 13.0 / 13.1 / 13.37 / 14.0 / 14.1 / current : ntp (SSA:2016-120-01)NessusSlackware Local Security Checks
high
90742FreeBSD : ntp -- multiple vulnerabilities (b2487d9a-0c30-11e6-acd0-d050996490d0)NessusFreeBSD Local Security Checks
high