CVE-2015-1799
published 2015-04-08CVE-2015-1799: The symmetric-key feature in the receive function in ntp_proto.c in ntpd in NTP 3.x and 4.x before 4.2.8p2 performs state-variable updates upon receiving…
PriorityP416medium4.3CVSS 2.0
AVAACMAuNCNIPAP
EPSS
0.90%
56.0th percentile
The symmetric-key feature in the receive function in ntp_proto.c in ntpd in NTP 3.x and 4.x before 4.2.8p2 performs state-variable updates upon receiving certain invalid packets, which makes it easier for man-in-the-middle attackers to cause a denial of service (synchronization loss) by spoofing the source IP address of a peer.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | os_x_yosemite_v10.10.4_and_security_update_2015-005 | — | — |
| cisco | products | — | — |
| debian | ntp | < ntp 1:4.2.6.p5+dfsg-6 (bullseye) | ntp 1:4.2.6.p5+dfsg-6 (bullseye) |
| ntp | ntp | <= 4.2.7p444 | — |
| ntp | ntp | >= 0 < 1:4.2.6.p5+dfsg-6 | 1:4.2.6.p5+dfsg-6 |
| ntp | ntp | >= 0 < 1:4.2.6.p5+dfsg-3ubuntu2.14.04.3 | 1:4.2.6.p5+dfsg-3ubuntu2.14.04.3 |
CVSS provenance
nvdv2.04.3MEDIUMAV:A/AC:M/Au:N/C:N/I:P/A:P
osv4.3MEDIUM
vendor_cisco4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
vendor_ubuntu1.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Rockwell Automation Stratix 5900
cisa_ics·2017-05-10
Rockwell Automation Stratix 5900
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Rockwell Automation Stratix 5900
Last RevisedMay 10, 2017
Alert CodeICSA-17-094-04
## CVSS v3 10.0
ATTENTION: Remotely exploitable/low skill level to exploit.
Vendor: Rockwell Automation
Equipment: Stratix 5900
Vulnerabilities: Improper Input Validation, Resource Management Errors, Improper Authentication, Path Traversal.
## REPOSTED INFORMATION
This advisory was originally posted to the NCCIC Portal on April 4, 2017, and is being released to the NCCIC/ICS-CERT web site.
## AFFECTED PRODUCTS
Rockwell Automation reports that these vulnerabilities affect the following Strat
Ubuntu
NTP vulnerabilities
vendor_ubuntu·2015-04-13·CVSS 1.8
CVE-2015-1798 [LOW] NTP vulnerabilities
Title: NTP vulnerabilities
Summary: Several security issues were fixed in NTP.
Miroslav Lichvar discovered that NTP incorrectly validated MAC fields. A
remote attacker could possibly use this issue to bypass authentication and
spoof packets. (CVE-2015-1798)
Miroslav Lichvar discovered that NTP incorrectly handled certain invalid
packets. A remote attacker could possibly use this issue to cause a denial
of service. (CVE-2015-1799)
Juergen Perlinger discovered that NTP incorrectly generated MD5 keys on
big-endian platforms. This issue could either cause ntp-keygen to hang, or
could result in non-random keys. (CVE number pending)
Instructions: In general, a standard system update will make all the necessary changes.
Cisco
Multiple Vulnerabilities in ntpd (April 2015) Affecting Cisco Products
vendor_cisco·2015-04-08·CVSS 1.8
CVE-2015-1798 [LOW] CWE-287 Multiple Vulnerabilities in ntpd (April 2015) Affecting Cisco Products
Multiple Vulnerabilities in ntpd (April 2015) Affecting Cisco Products
Multiple Cisco products incorporate a version of the ntpd package. Versions of this package are affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to bypass authentication controls or to create a denial of service (DoS) condition.
On April 7, 2015, NTP.org and US-CERT released a security advisory dealing with two issues regarding bypass of authentication controls. These vulnerabilities are referenced in this document as follows:
CVE-2015-1798: NTP Authentication bypass vulnerability
CVE-2015-1799: NTP Authentication doesn't protect symmetric associations against DoS attacks
Cisco has released software updates that address these vulnerabilities.
Workarounds that mitigate the
Cisco
Network Time Protocol Daemon Symmetric Mode Packet Processing Denial of Service Vulnerability
vendor_cisco·2015-04-08·CVSS 4.3
CVE-2015-1799 [MEDIUM] CWE-287 Network Time Protocol Daemon Symmetric Mode Packet Processing Denial of Service Vulnerability
Network Time Protocol Daemon Symmetric Mode Packet Processing Denial of Service Vulnerability
A vulnerability in ntpd could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected system.
The vulnerability is due to improper processing of Network Time Protocol (NTP) packets when handling symmetric key authentication failures. An attacker could exploit this vulnerability by conducting a man-in-the-middle attack to periodically transmit crafted NTP packets with set NTP state variables. An exploit could allow the attacker to disrupt communication between NTP hosts, preventing synchronization and leading to a DoS condition for legitimate users.
NTP.org has confirmed this vulnerability in a security advisory and released software updates.
To
BSD
FreeBSD-SA-15:07.ntp: Multiple vulnerabilities of ntp
bsd_advisories·2015-04-07·CVSS 1.8
CVE-2014-9297 [LOW] FreeBSD-SA-15:07.ntp: Multiple vulnerabilities of ntp
FreeBSD-SA-15:07.ntp Security Advisory
The FreeBSD Project
Topic: Multiple vulnerabilities of ntp
Category: contrib
Module: ntp
Announced: 2015-04-07
Credits: Network Time Foundation
Affects: All supported versions of FreeBSD.
Corrected: 2015-04-07 20:20:24 UTC (stable/10, 10.1-STABLE)
2015-04-07 20:21:01 UTC (releng/10.1, 10.1-RELEASE-p9)
2015-04-07 20:20:44 UTC (stable/9, 9.3-STABLE)
2015-04-07 20:21:23 UTC (releng/9.3, 9.3-RELEASE-p13)
2015-04-07 20:20:44 UTC (stable/8, 8.4-STABLE)
2015-04-07 20:21:23 UTC (releng/8.4, 8.4-RELEASE-p27)
CVE Name: CVE-2014-9297, CVE-2015-1798, CVE-2015-1799
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Background
The ntpd(8) da
Red Hat
ntp: authentication doesn't protect symmetric associations against DoS attacks
vendor_redhat·2015-04-07·CVSS 4.3
CVE-2015-1799 [MEDIUM] ntp: authentication doesn't protect symmetric associations against DoS attacks
ntp: authentication doesn't protect symmetric associations against DoS attacks
The symmetric-key feature in the receive function in ntp_proto.c in ntpd in NTP 3.x and 4.x before 4.2.8p2 performs state-variable updates upon receiving certain invalid packets, which makes it easier for man-in-the-middle attackers to cause a denial of service (synchronization loss) by spoofing the source IP address of a peer.
A denial of service flaw was found in the way NTP hosts that were peering with each other authenticated themselves before updating their internal state variables. An attacker could send packets to one peer host, which could cascade to other peers, and stop the synchronization process among the reached peers.
Mitigation: To work around this issue, instead of configuring NTP hosts as pee
Debian
CVE-2015-1799: ntp - The symmetric-key feature in the receive function in ntp_proto.c in ntpd in NTP ...
vendor_debian·2015·CVSS 4.3
CVE-2015-1799 [MEDIUM] CVE-2015-1799: ntp - The symmetric-key feature in the receive function in ntp_proto.c in ntpd in NTP ...
The symmetric-key feature in the receive function in ntp_proto.c in ntpd in NTP 3.x and 4.x before 4.2.8p2 performs state-variable updates upon receiving certain invalid packets, which makes it easier for man-in-the-middle attackers to cause a denial of service (synchronization loss) by spoofing the source IP address of a peer.
Scope: local
bullseye: resolved (fixed in 1:4.2.6.p5+dfsg-6)
Apple
CVE-2015-1799: OS X Yosemite v10.10.4 and Security Update 2015-005
vendor_apple·CVSS 4.3
CVE-2015-1799 [MEDIUM] CVE-2015-1799: OS X Yosemite v10.10.4 and Security Update 2015-005
Apple Security Update: About the security content of OS X Yosemite v10.10.4 and Security Update 2015-005
Product: OS X Yosemite v10.10.4 and Security Update 2015-005
CVE: CVE-2015-1799
Component: CVE-2015-1799
Cisco
Multiple Vulnerabilities in ntpd (April 2015) Affecting Cisco Products
vendor_cisco
CVE-2015-1799 Multiple Vulnerabilities in ntpd (April 2015) Affecting Cisco Products
CVE-2015-1799: Multiple Vulnerabilities in ntpd (April 2015) Affecting Cisco Products
Multiple Cisco products incorporate a version of the ntpd package. Versions of this package are affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to bypass authentication controls or to create a denial of service (DoS) condition. On April 7, 2015, NTP.org and US-CERT released a security advisory dealing with two issues regarding bypass of authentication controls. These vulnerabilities are referenced in this document as follows: CVE-2015-1798: NTP Authentication bypass vulnerability CVE-2015-1799: NTP Authentication doesn't protect symmetric associations against DoS attacks Cisco has released software updates that address these vulnerabilities.
CWE: CWE-287, CWE-2
Cisco
Multiple Vulnerabilities in ntpd (April 2015) Affecting Cisco Products
vendor_cisco
CVE-2015-1798 Multiple Vulnerabilities in ntpd (April 2015) Affecting Cisco Products
CVE-2015-1798: Multiple Vulnerabilities in ntpd (April 2015) Affecting Cisco Products
Multiple Cisco products incorporate a version of the ntpd package. Versions of this package are affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to bypass authentication controls or to create a denial of service (DoS) condition. On April 7, 2015, NTP.org and US-CERT released a security advisory dealing with two issues regarding bypass of authentication controls. These vulnerabilities are referenced in this document as follows: CVE-2015-1798: NTP Authentication bypass vulnerability CVE-2015-1799: NTP Authentication doesn't protect symmetric associations against DoS attacks Cisco has released software updates that address these vulnerabilities.
CWE: CWE-287, CWE-2
GHSA
GHSA-q9p8-4cvj-q5fj: The symmetric-key feature in the receive function in ntp_proto
ghsa_unreviewed·2022-05-14
CVE-2015-1799 [MEDIUM] GHSA-q9p8-4cvj-q5fj: The symmetric-key feature in the receive function in ntp_proto
The symmetric-key feature in the receive function in ntp_proto.c in ntpd in NTP 3.x and 4.x before 4.2.8p2 performs state-variable updates upon receiving certain invalid packets, which makes it easier for man-in-the-middle attackers to cause a denial of service (synchronization loss) by spoofing the source IP address of a peer.
OSV
ntp vulnerabilities
osv·2015-04-13·CVSS 1.8
CVE-2015-1798 [LOW] ntp vulnerabilities
ntp vulnerabilities
Miroslav Lichvar discovered that NTP incorrectly validated MAC fields. A
remote attacker could possibly use this issue to bypass authentication and
spoof packets. (CVE-2015-1798)
Miroslav Lichvar discovered that NTP incorrectly handled certain invalid
packets. A remote attacker could possibly use this issue to cause a denial
of service. (CVE-2015-1799)
Juergen Perlinger discovered that NTP incorrectly generated MD5 keys on
big-endian platforms. This issue could either cause ntp-keygen to hang, or
could result in non-random keys. (CVE number pending)
OSV
CVE-2015-1799: The symmetric-key feature in the receive function in ntp_proto
osv·2015-04-08·CVSS 4.3
CVE-2015-1799 [MEDIUM] CVE-2015-1799: The symmetric-key feature in the receive function in ntp_proto
The symmetric-key feature in the receive function in ntp_proto.c in ntpd in NTP 3.x and 4.x before 4.2.8p2 performs state-variable updates upon receiving certain invalid packets, which makes it easier for man-in-the-middle attackers to cause a denial of service (synchronization loss) by spoofing the source IP address of a peer.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-1798 CVE-2015-1799 ntp: various flaws [fedora-all]
bugzilla·2015-04-07·CVSS 1.8
CVE-2015-1798 [LOW] CVE-2015-1798 CVE-2015-1799 ntp: various flaws [fedora-all]
CVE-2015-1798 CVE-2015-1799 ntp: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While only
Bugzilla
CVE-2015-1799 ntp: authentication doesn't protect symmetric associations against DoS attacks
bugzilla·2015-03-06·CVSS 4.3
CVE-2015-1799 [MEDIUM] CVE-2015-1799 ntp: authentication doesn't protect symmetric associations against DoS attacks
CVE-2015-1799 ntp: authentication doesn't protect symmetric associations against DoS attacks
An attacker knowing that NTP hosts A and B are peering with each other (symmetric association) can send a packet to host A with source address of B which will set the NTP state variables on A to the values sent by the attacker. Host A will then send on its next poll to B a packet with originate timestamp that doesn't match the transmit timestamp of B and the packet will be dropped. If the attacker does this periodically for both hosts, they won't be able to synchronize to each other. This is a known denial-of-service attack, described at [1].
According to the document the NTP authentication is supposed to protect symmetric associations against this attack, but that doesn't seem to be the case. Th
http://bugs.ntp.org/show_bug.cgi?id=2781http://listengine.tuxfamily.org/chrony.tuxfamily.org/chrony-announce/2015/04/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2015/Jun/msg00002.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-April/155863.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-April/155864.htmlhttp://lists.opensuse.org/opensuse-updates/2015-04/msg00052.htmlhttp://marc.info/?l=bugtraq&m=143213867103400&w=2http://marc.info/?l=bugtraq&m=145750740530849&w=2http://rhn.redhat.com/errata/RHSA-2015-1459.htmlhttp://support.apple.com/kb/HT204942http://support.ntp.org/bin/view/Main/SecurityNotice#Recent_Vulnerabilitieshttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150408-ntpdhttp://tools.cisco.com/security/center/viewAlert.x?alertId=38275http://www.debian.org/security/2015/dsa-3222http://www.debian.org/security/2015/dsa-3223http://www.kb.cert.org/vuls/id/374268http://www.mandriva.com/security/advisories?name=MDVSA-2015:202http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/73950http://www.securitytracker.com/id/1032031http://www.ubuntu.com/usn/USN-2567-1https://kc.mcafee.com/corporate/index?page=content&id=SB10114https://security.gentoo.org/glsa/201509-01http://bugs.ntp.org/show_bug.cgi?id=2781http://listengine.tuxfamily.org/chrony.tuxfamily.org/chrony-announce/2015/04/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2015/Jun/msg00002.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-April/155863.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-April/155864.htmlhttp://lists.opensuse.org/opensuse-updates/2015-04/msg00052.htmlhttp://marc.info/?l=bugtraq&m=143213867103400&w=2http://marc.info/?l=bugtraq&m=145750740530849&w=2http://rhn.redhat.com/errata/RHSA-2015-1459.htmlhttp://support.apple.com/kb/HT204942http://support.ntp.org/bin/view/Main/SecurityNotice#Recent_Vulnerabilitieshttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150408-ntpdhttp://tools.cisco.com/security/center/viewAlert.x?alertId=38275http://www.debian.org/security/2015/dsa-3222http://www.debian.org/security/2015/dsa-3223http://www.kb.cert.org/vuls/id/374268http://www.mandriva.com/security/advisories?name=MDVSA-2015:202http://www.oracle.com/technetwork/topics/security/bulletinapr2015-2511959.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/73950http://www.securitytracker.com/id/1032031http://www.ubuntu.com/usn/USN-2567-1https://kc.mcafee.com/corporate/index?page=content&id=SB10114https://security.gentoo.org/glsa/201509-01
2015-04-08
Published