CVE-2016-1384
published 2016-04-20CVE-2016-1384: The NTP implementation in Cisco IOS 15.1 and 15.5 and IOS XE 3.2 through 3.17 allows remote attackers to modify the system time via crafted packets, aka Bug ID…
PriorityP340high7.5CVSS 3.0
AVNACLPRNUINSUCNIHAN
EPSS
2.49%
83.0th percentile
The NTP implementation in Cisco IOS 15.1 and 15.5 and IOS XE 3.2 through 3.17 allows remote attackers to modify the system time via crafted packets, aka Bug ID CSCux46898.
Affected
188 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x2rg-98fw-rff3: The NTP implementation in Cisco IOS 15
ghsa_unreviewed·2022-05-17
CVE-2016-1384 [HIGH] GHSA-x2rg-98fw-rff3: The NTP implementation in Cisco IOS 15
The NTP implementation in Cisco IOS 15.1 and 15.5 and IOS XE 3.2 through 3.17 allows remote attackers to modify the system time via crafted packets, aka Bug ID CSCux46898.
Cisco
Cisco IOS and Cisco IOS XE ntp Subsystem Unauthorized Access Vulnerability
vendor_cisco·2016-04-19·CVSS 4.3
CVE-2016-1384 [MEDIUM] CWE-264 Cisco IOS and Cisco IOS XE ntp Subsystem Unauthorized Access Vulnerability
Cisco IOS and Cisco IOS XE ntp Subsystem Unauthorized Access Vulnerability
A vulnerability in the ntp subsystem of Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to mobilize ntp associations.
The vulnerability is due to missing authorization checks on certain ntp packets. An attacker could exploit this vulnerability by ingressing malicious packets to the ntp daemon. An exploit could allow the attacker to control the time of the affected device.
Cisco has released software updates that address this vulnerability. Workarounds that address this vulnerability are not available.
This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160419-ios
Cisco
Cisco IOS and Cisco IOS XE ntp Subsystem Unauthorized Access Vulnerability
vendor_cisco
CVE-2016-1384 Cisco IOS and Cisco IOS XE ntp Subsystem Unauthorized Access Vulnerability
CVE-2016-1384: Cisco IOS and Cisco IOS XE ntp Subsystem Unauthorized Access Vulnerability
A vulnerability in the ntp subsystem of Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to mobilize ntp associations. The vulnerability is due to missing authorization checks on certain ntp packets. An attacker could exploit this vulnerability by ingressing malicious packets to the ntp daemon. An exploit could allow the attacker to control the time of the affected device. Cisco has released software updates that address this vulnerability.
CWE: CWE-264, CWE-264
Bug IDs: CSCux46898
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/86685http://www.securitytracker.com/id/1035622https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160419-ioshttp://www.securityfocus.com/bid/86685http://www.securitytracker.com/id/1035622https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160419-ios
2016-04-20
Published