Cisco Prime LAN Management Solution ntpd Multiple Vulnerabilities

high Nessus Plugin ID 83877

Synopsis

A network management system on the remote host is affected by multiple vulnerabilities.

Description

According to its self-reported version number, the Cisco Prime LAN Management Solution running on the remote host is affected by multiple vulnerabilities :

- A security weakness exists due to the config_auth() function improperly generating default keys when no authentication key is defined in the 'ntp.conf' file.
Key size is limited to 31 bits and the insecure ntp_random() function is used, resulting in cryptographically weak keys with insufficient entropy.
This allows a remote attacker to defeat cryptographic protection mechanisms via a brute-force attack.
(CVE-2014-9293)

- A security weakness exists due the use of a weak seed to prepare a random number generator used to generate symmetric keys. This allows remote attackers to defeat cryptographic protection mechanisms via a brute-force attack. (CVE-2014-9294)

- Multiple stack-based buffer overflows exist due to improperly validated user-supplied input when handling packets in the crypto_recv(), ctl_putdata(), and configure() functions when using autokey authentication.
This allows a remote attacker, via a specially crafted packet, to cause a denial of service condition or execute arbitrary code. (CVE-2014-9295)

- A unspecified vulnerability exists due to missing return statements in the receive() function, resulting in continued processing even when an authentication error is encountered. This allows a remote attacker, via crafted packets, to trigger unintended association changes. (CVE-2014-9296)

Solution

Upgrade to Cisco Prime LMS 4.2(5.3) or later.

See Also

http://www.nessus.org/u?292ffa4a

Plugin Details

Severity: High

ID: 83877

File Name: cisco_prime_lms_sa-20141222-ntpd.nasl

Version: 1.7

Type: remote

Family: CISCO

Published: 5/28/2015

Updated: 11/15/2018

Configuration: Enable paranoid mode

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: cpe:/a:cisco:prime_lan_management_solution

Required KB Items: Settings/ParanoidReport, www/cisco_lms

Exploit Ease: No known exploits are available

Patch Publication Date: 4/1/2015

Vulnerability Publication Date: 12/19/2014

Reference Information

CVE: CVE-2014-9293, CVE-2014-9294, CVE-2014-9295, CVE-2014-9296

BID: 71757, 71758, 71761, 71762

CERT: 852879

CISCO-SA: cisco-sa-20141222-ntpd

CISCO-BUG-ID: CSCus27300