CVE-2016-1551

LOW

Description

ntpd in NTP 4.2.8p3 and NTPsec a5fb34b9cc89b92a8fef2f459004865c93bb7f92 relies on the underlying operating system to protect it from requests that impersonate reference clocks. Because reference clocks are treated like other peers and stored in the same structure, any packet with a source ip address of a reference clock (127.127.1.1 for example) that reaches the receive() function will match that reference clock's peer record and will be treated as a trusted peer. Any system that lacks the typical martian packet filtering which would block these packets is in danger of having its time controlled by an attacker.

References

http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html

http://www.securityfocus.com/bid/88219

http://www.securitytracker.com/id/1035705

http://www.talosintelligence.com/reports/TALOS-2016-0132/

https://security.FreeBSD.org/advisories/FreeBSD-SA-16:16.ntp.asc

https://security.gentoo.org/glsa/201607-15

https://security.netapp.com/advisory/ntap-20171004-0002/

Details

Source: MITRE

Published: 2017-01-27

Updated: 2017-11-21

Type: CWE-254

Risk Information

CVSS v2.0

Base Score: 2.6

Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N

Impact Score: 2.9

Exploitability Score: 4.9

Severity: LOW

CVSS v3.0

Base Score: 3.7

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

Impact Score: 1.4

Exploitability Score: 2.2

Severity: LOW

Tenable Plugins

View all (18 total)

IDNameProductFamilySeverity
104100Juniper Junos Space < 17.1R1 Multiple Vulnerabilities (JSA10826)NessusJunos Local Security Checks
high
102128AIX NTP v3 Advisory : ntp_advisory7.asc (IV87614) (IV87419) (IV87615) (IV87420) (IV87939)NessusAIX Local Security Checks
medium
99183AIX NTP v4 Advisory : ntp_advisory7.asc (IV87278) (IV87279)NessusAIX Local Security Checks
medium
93352AIX 7.2 TL 0 : ntp (IV87939) (deprecated)NessusAIX Local Security Checks
medium
93351AIX 7.1 TL 3 : ntp (IV87615) (deprecated)NessusAIX Local Security Checks
medium
93350AIX 5.3 TL 12 : ntp (IV87614) (deprecated)NessusAIX Local Security Checks
medium
93349AIX 7.1 TL 4 : ntp (IV87420) (deprecated)NessusAIX Local Security Checks
medium
93348AIX 6.1 TL 9 : ntp (IV87419) (deprecated)NessusAIX Local Security Checks
medium
93186SUSE SLES10 Security Update : ntp (SUSE-SU-2016:1912-1)NessusSuSE Local Security Checks
high
92485GLSA-201607-15 : NTP: Multiple vulnerabilitiesNessusGentoo Local Security Checks
high
91663SUSE SLED12 / SLES12 Security Update : ntp (SUSE-SU-2016:1568-1)NessusSuSE Local Security Checks
high
91403openSUSE Security Update : ntp (openSUSE-2016-649)NessusSuSE Local Security Checks
high
91269openSUSE Security Update : ntp (openSUSE-2016-599)NessusSuSE Local Security Checks
high
91159SUSE SLED12 / SLES12 Security Update : ntp (SUSE-SU-2016:1291-1)NessusSuSE Local Security Checks
high
91120SUSE SLES11 Security Update : ntp (SUSE-SU-2016:1278-1)NessusSuSE Local Security Checks
high
90923Network Time Protocol Daemon (ntpd) 3.x / 4.x < 4.2.8p7 Multiple VulnerabilitiesNessusMisc.
high
90800Slackware 13.0 / 13.1 / 13.37 / 14.0 / 14.1 / current : ntp (SSA:2016-120-01)NessusSlackware Local Security Checks
high
90742FreeBSD : ntp -- multiple vulnerabilities (b2487d9a-0c30-11e6-acd0-d050996490d0)NessusFreeBSD Local Security Checks
high