CVE-2016-1549
published 2017-01-06CVE-2016-1549: A malicious authenticated peer can create arbitrarily-many ephemeral associations in order to win the clock selection algorithm in ntpd in NTP 4.2.8p4 and…
PriorityP335medium6.5CVSS 3.0
AVNACLPRLUINSUCNIHAN
EPSS
3.15%
86.6th percentile
A malicious authenticated peer can create arbitrarily-many ephemeral associations in order to win the clock selection algorithm in ntpd in NTP 4.2.8p4 and earlier and NTPsec 3e160db8dc248a0bcb053b56a80167dc742d2b74 and a5fb34b9cc89b92a8fef2f459004865c93bb7f92 and modify a victim's clock.
Affected
33 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ntp | < ntp 1:4.2.8p7+dfsg-1 (bullseye) | ntp 1:4.2.8p7+dfsg-1 (bullseye) |
| debian | ntp | < ntp 1:4.2.8p11+dfsg-1 (bullseye) | ntp 1:4.2.8p11+dfsg-1 (bullseye) |
| debian | ntpsec | < ntp 1:4.2.8p11+dfsg-1 (bullseye) | ntp 1:4.2.8p11+dfsg-1 (bullseye) |
| hpe | hpux-ntp | < c.4.2.8.4.0 | c.4.2.8.4.0 |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | — | — |
| ntp | ntp | >= 0 < 1:4.2.8p11+dfsg-1 | 1:4.2.8p11+dfsg-1 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_cisco5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
ntp: Ephemeral association time spoofing additional protection
vendor_redhat·2018-02-27·CVSS 6.5
CVE-2018-7170 [MEDIUM] ntp: Ephemeral association time spoofing additional protection
ntp: Ephemeral association time spoofing additional protection
ntpd in ntp 4.2.x before 4.2.8p7 and 4.3.x before 4.3.92 allows authenticated users that know the private symmetric key to create arbitrarily-many ephemeral associations in order to win the clock selection of ntpd and modify a victim's clock via a Sybil attack. This issue exists because of an incomplete fix for CVE-2016-1549.
A flaw was found in ntpd making it vulnerable to Sybil attacks. An authenticated attacker could target systems configured to use a trusted key in certain configurations and to create an arbitrary number of associations and subsequently modify a victim's clock.
Package: ntp (Red Hat Enterprise Linux 5) - Will not fix
Package: ntp (Red Hat Enterprise Linux 6) - Will not fix
Package: ntp (Red Hat Enterpr
Debian
CVE-2018-7170: ntp - ntpd in ntp 4.2.x before 4.2.8p7 and 4.3.x before 4.3.92 allows authenticated us...
vendor_debian·2018·CVSS 6.5
CVE-2018-7170 [MEDIUM] CVE-2018-7170: ntp - ntpd in ntp 4.2.x before 4.2.8p7 and 4.3.x before 4.3.92 allows authenticated us...
ntpd in ntp 4.2.x before 4.2.8p7 and 4.3.x before 4.3.92 allows authenticated users that know the private symmetric key to create arbitrarily-many ephemeral associations in order to win the clock selection of ntpd and modify a victim's clock via a Sybil attack. This issue exists because of an incomplete fix for CVE-2016-1549.
Scope: local
bullseye: resolved (fixed in 1:4.2.8p11+dfsg-1)
BSD
FreeBSD-SA-16:16.ntp: Multiple vulnerabilities of ntp
bsd_advisories·2016-04-29·CVSS 5.3
CVE-2016-1547 [MEDIUM] FreeBSD-SA-16:16.ntp: Multiple vulnerabilities of ntp
FreeBSD-SA-16:16.ntp Security Advisory
The FreeBSD Project
Topic: Multiple vulnerabilities of ntp
Category: contrib
Module: ntp
Announced: 2016-04-29
Credits: Network Time Foundation and various contributors listed below
Affects: All supported versions of FreeBSD.
Corrected: 2016-04-27 15:24:33 UTC (stable/10, 10.3-STABLE)
2016-04-29 08:02:31 UTC (releng/10.3, 10.3-RELEASE-p1)
2016-04-29 08:02:31 UTC (releng/10.2, 10.2-RELEASE-p15)
2016-04-29 08:02:31 UTC (releng/10.1, 10.1-RELEASE-p32)
2016-04-27 15:25:18 UTC (stable/9, 9.3-STABLE)
2016-04-29 08:02:31 UTC (releng/9.3, 9.3-RELEASE-p40)
CVE Name: CVE-2016-1547, CVE-2016-1548, CVE-2016-1549, CVE-2016-1550,
CVE-2016-1551, CVE-2016-2516, CVE-2016-2517, CVE-2016-2518,
CVE-2016-2519
For general information regarding FreeBSD Security Advisorie
Cisco
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: April 2016
vendor_cisco·2016-04-28·CVSS 5.3
CVE-2015-7704 [MEDIUM] Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: April 2016
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: April 2016
Multiple Cisco products incorporate a version of the Network Time Protocol daemon (ntpd) package. Versions of this package are affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or modify the time being advertised by a device acting as a Network Time Protocol (NTP) server.
On April 26, 2016, the NTP Consortium of the Network Time Foundation released a security notice that details 11 issues regarding DoS vulnerabilities, information disclosure vulnerabilities, and logic issues that may allow an attacker to shift a system's time. Two of the vulnerabilities disclosed in the NTP security notice address issues that
Red Hat
ntp: ephemeral association time spoofing
vendor_redhat·2016-04-26·CVSS 6.5
CVE-2016-1549 [MEDIUM] ntp: ephemeral association time spoofing
ntp: ephemeral association time spoofing
A malicious authenticated peer can create arbitrarily-many ephemeral associations in order to win the clock selection algorithm in ntpd in NTP 4.2.8p4 and earlier and NTPsec 3e160db8dc248a0bcb053b56a80167dc742d2b74 and a5fb34b9cc89b92a8fef2f459004865c93bb7f92 and modify a victim's clock.
Statement: Red Hat Product Security has rated this issue as having Low security impact: to exploit this issue, an attacker must have access to a trustedkey if one is configured in the /etc/ntp.key file. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Mitigation: Assure only trusted hosts have access to the trus
Debian
CVE-2016-1549: ntp - A malicious authenticated peer can create arbitrarily-many ephemeral association...
vendor_debian·2016·CVSS 6.5
CVE-2016-1549 [MEDIUM] CVE-2016-1549: ntp - A malicious authenticated peer can create arbitrarily-many ephemeral association...
A malicious authenticated peer can create arbitrarily-many ephemeral associations in order to win the clock selection algorithm in ntpd in NTP 4.2.8p4 and earlier and NTPsec 3e160db8dc248a0bcb053b56a80167dc742d2b74 and a5fb34b9cc89b92a8fef2f459004865c93bb7f92 and modify a victim's clock.
Scope: local
bullseye: resolved (fixed in 1:4.2.8p7+dfsg-1)
Cisco
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: April 2016
vendor_cisco
CVE-2016-1549 Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: April 2016
CVE-2016-1549: Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: April 2016
Multiple Cisco products incorporate a version of the Network Time Protocol daemon (ntpd) package. Versions of this package are affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or modify the time being advertised by a device acting as a Network Time Protocol (NTP) server. On April 26, 2016, the NTP Consortium of the Network Time Foundation released a security notice that
Bug IDs: CSCuz44082, CSCuz44085, CSCuz44088, CSCuz44082, CSCuz44085
GHSA
GHSA-r89j-r995-h68w: A malicious authenticated peer can create arbitrarily-many ephemeral associations in order to win the clock selection algorithm in ntpd in NTP 4
ghsa_unreviewed·2022-05-14
CVE-2016-1549 [MEDIUM] GHSA-r89j-r995-h68w: A malicious authenticated peer can create arbitrarily-many ephemeral associations in order to win the clock selection algorithm in ntpd in NTP 4
A malicious authenticated peer can create arbitrarily-many ephemeral associations in order to win the clock selection algorithm in ntpd in NTP 4.2.8p4 and earlier and NTPsec 3e160db8dc248a0bcb053b56a80167dc742d2b74 and a5fb34b9cc89b92a8fef2f459004865c93bb7f92 and modify a victim's clock.
GHSA
GHSA-v9cv-3r4j-cx4j: ntpd in ntp 4
ghsa_unreviewed·2022-05-13·CVSS 6.5
CVE-2018-7170 [MEDIUM] GHSA-v9cv-3r4j-cx4j: ntpd in ntp 4
ntpd in ntp 4.2.x before 4.2.8p7 and 4.3.x before 4.3.92 allows authenticated users that know the private symmetric key to create arbitrarily-many ephemeral associations in order to win the clock selection of ntpd and modify a victim's clock via a Sybil attack. This issue exists because of an incomplete fix for CVE-2016-1549.
OSV
CVE-2018-7170: ntpd in ntp 4
osv·2018-03-06·CVSS 6.5
CVE-2018-7170 [MEDIUM] CVE-2018-7170: ntpd in ntp 4
ntpd in ntp 4.2.x before 4.2.8p7 and 4.3.x before 4.3.92 allows authenticated users that know the private symmetric key to create arbitrarily-many ephemeral associations in order to win the clock selection of ntpd and modify a victim's clock via a Sybil attack. This issue exists because of an incomplete fix for CVE-2016-1549.
OSV
CVE-2016-1549: A malicious authenticated peer can create arbitrarily-many ephemeral associations in order to win the clock selection algorithm in ntpd in NTP 4
osv·2017-01-06·CVSS 6.5
CVE-2016-1549 [MEDIUM] CVE-2016-1549: A malicious authenticated peer can create arbitrarily-many ephemeral associations in order to win the clock selection algorithm in ntpd in NTP 4
A malicious authenticated peer can create arbitrarily-many ephemeral associations in order to win the clock selection algorithm in ntpd in NTP 4.2.8p4 and earlier and NTPsec 3e160db8dc248a0bcb053b56a80167dc742d2b74 and a5fb34b9cc89b92a8fef2f459004865c93bb7f92 and modify a victim's clock.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-7170 ntp: Ephemeral association time spoofing additional protection
bugzilla·2018-02-28·CVSS 6.5
CVE-2018-7170 [MEDIUM] CVE-2018-7170 ntp: Ephemeral association time spoofing additional protection
CVE-2018-7170 ntp: Ephemeral association time spoofing additional protection
ntpd can be vulnerable to Sybil attacks. If a system is set up to use a trustedkey and if one is not using the feature introduced in ntp-4.2.8p6 allowing an optional 4th field in the ntp.keys file to specify which IPs can serve time, a malicious authenticated peer -- i.e. one where the attacker knows the private symmetric key -- can create arbitrarily-many ephemeral associations in order to win the clock selection of ntpd and modify a victim's clock.
Ps.: This is possibly a incomplete fix for CVE-2016-1549.
References:
http://support.ntp.org/bin/view/Main/NtpBug3415
Discussion:
Created ntp tracking bugs for this issue:
Affects: fedora-all [bug 1550228]
Bugzilla
CVE-2016-1548 CVE-2016-1549 CVE-2016-1550 CVE-2016-2516 CVE-2016-2517 CVE-2016-2518 ntp: various flaws [fedora-all]
bugzilla·2016-05-02·CVSS 7.2
CVE-2016-1548 [HIGH] CVE-2016-1548 CVE-2016-1549 CVE-2016-1550 CVE-2016-2516 CVE-2016-2517 CVE-2016-2518 ntp: various flaws [fedora-all]
CVE-2016-1548 CVE-2016-1549 CVE-2016-1550 CVE-2016-2516 CVE-2016-2517 CVE-2016-2518 ntp: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue a
Bugzilla
CVE-2016-1549 ntp: ephemeral association time spoofing
bugzilla·2016-04-28·CVSS 6.5
CVE-2016-1549 [MEDIUM] CVE-2016-1549 ntp: ephemeral association time spoofing
CVE-2016-1549 ntp: ephemeral association time spoofing
The following flaw was found in ntpd:
ntpd can be vulnerable to Sybil attacks. If a system is set up to use a trustedkey and if one is not using the feature introduced in ntp-4.2.8p6 allowing an optional 4th field in the ntp.keys file to specify which IPs can serve time, a malicious authenticated peer -- i.e. one where the attacker knows the private symmetric key -- can create arbitrarily-many ephemeral associations in order to win the clock selection of ntpd and modify a victim's clock.
Upstream bugs:
http://support.ntp.org/bin/view/Main/NtpBug3012
External References:
http://support.ntp.org/bin/view/Main/SecurityNotice#April_2016_NTP_4_2_8p7_Security
http://www.talosintel.com/reports/TALOS-2016-0083/
Discussion:
Created ntp t
Talos
Vulnerability Spotlight: Further NTPD Vulnerabilities
blogs_talos·2016-04-27·CVSS 5.3
[MEDIUM] Vulnerability Spotlight: Further NTPD Vulnerabilities
## Vulnerability Spotlight: Further NTPD Vulnerabilities
As a member of the Linux Foundation Core Infrastructure Initiative , Cisco is contributing to the CII effort by evaluating the Network Time Protocol daemon (ntpd) for security defects. We previously identified a series of vulnerabilities in the Network Time Protocol daemon; through our continued research we have identified further vulnerabilities in the software.
Since 2013, criminals have been abusing NTP packets in order to cause amplified denial of service attacks . The ubiquity of the Network Time Protocol daemon and the importance of co-ordinated time for the correct functioning of many services means that it is a tempting target for attack. Vulnerabilities that allow the time as understood by ntpd to be altered can be used by
Talos
Vulnerability Spotlight: Further NTPD Vulnerabilities
blogs_talos·2016-04-27·CVSS 5.3
[MEDIUM] Vulnerability Spotlight: Further NTPD Vulnerabilities
As a member of the Linux Foundation Core Infrastructure Initiative, Cisco is contributing to the CII effort by evaluating the Network Time Protocol daemon (ntpd) for security defects. We previously identified a series of vulnerabilities in the Network Time Protocol daemon; through our continued research we have identified further vulnerabilities in the software.
Since 2013, criminals have been abusing NTP packets in order to cause amplified denial of service attacks. The ubiquity of the Network Time Protocol daemon and the importance of co-ordinated time for the correct functioning of many services means that it is a tempting target for attack. Vulnerabilities that allow the time as understood by ntpd to be altered can be used by attackers to set the time to an arbitrary value. This allow
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/88200http://www.securitytracker.com/id/1035705http://www.talosintelligence.com/reports/TALOS-2016-0083/https://security.FreeBSD.org/advisories/FreeBSD-SA-16:16.ntp.aschttps://security.gentoo.org/glsa/201607-15https://security.netapp.com/advisory/ntap-20171004-0002/https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03962en_ushttps://www.synology.com/support/security/Synology_SA_18_13http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/88200http://www.securitytracker.com/id/1035705http://www.talosintelligence.com/reports/TALOS-2016-0083/https://security.FreeBSD.org/advisories/FreeBSD-SA-16:16.ntp.aschttps://security.gentoo.org/glsa/201607-15https://security.netapp.com/advisory/ntap-20171004-0002/https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03962en_ushttps://www.synology.com/support/security/Synology_SA_18_13
2017-01-06
Published