CVE-2016-4953
published 2016-07-05CVE-2016-4953: ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (ephemeral-association demobilization) by sending a spoofed crypto-NAK…
PriorityP350high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
17.24%
96.7th percentile
ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (ephemeral-association demobilization) by sending a spoofed crypto-NAK packet with incorrect authentication data at a certain time.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ntp | < ntp 1:4.2.8p8+dfsg-1 (bullseye) | ntp 1:4.2.8p8+dfsg-1 (bullseye) |
| ntp | ntp | — | — |
| ntp | ntp | >= 0 < 1:4.2.8p8+dfsg-1 | 1:4.2.8p8+dfsg-1 |
| ntp | ntp | >= 4.2.0 < 4.2.8 | 4.2.8 |
| ntp | ntp | >= 4.3.0 < 4.3.93 | 4.3.93 |
| opensuse | leap | — | — |
| opensuse | opensuse | — | — |
| oracle | solaris | — | — |
| oracle | solaris | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_server | — | — |
| suse | manager | — | — |
| suse | manager_proxy | — | — |
| suse | openstack_cloud | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-26jw-7mv6-89rj: ntpd in NTP 4
ghsa_unreviewed·2022-05-13
CVE-2016-4953 [HIGH] CWE-287 GHSA-26jw-7mv6-89rj: ntpd in NTP 4
ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (ephemeral-association demobilization) by sending a spoofed crypto-NAK packet with incorrect authentication data at a certain time.
OSV
CVE-2016-4953: ntpd in NTP 4
osv·2016-07-05·CVSS 7.5
CVE-2016-4953 [HIGH] CVE-2016-4953: ntpd in NTP 4
ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (ephemeral-association demobilization) by sending a spoofed crypto-NAK packet with incorrect authentication data at a certain time.
CISA ICS
Siemens SIMATIC NET CP 443-1 OPC UA
cisa_ics·2021-06-08·CVSS 5.9
[MEDIUM] Siemens SIMATIC NET CP 443-1 OPC UA
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SIMATIC NET CP 443-1 OPC UA
Last RevisedJune 08, 2021
Alert CodeICSA-21-159-11
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC NET CP 443-1 OPC UA
- Vulnerabilities: Improper Input Validation, Improper Restriction of Operations within the Bounds of a Memory Buffer, Incorrect Calculation, Classic Buffer Overflow, Improper Authentication, Race Condition, Data Processing Errors, Exposure of Sensitive Information to an Unauthorized Actor, Out-of-bounds Read
## 2. RISK EVALUATION
Succes
CISA ICS
Siemens TIM 4R-IE Devices
cisa_ics·2021-04-13·CVSS 7.5
[HIGH] Siemens TIM 4R-IE Devices
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens TIM 4R-IE Devices
Last RevisedApril 13, 2021
Alert CodeICSA-21-103-11
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: TIM 4R-IE
- Vulnerabilities: Incorrect Type Conversion or Cast, Improper Input Validation, Improper Authentication, Security Features, Null Pointer Dereference, Data Processing Errors, Exposure of Sensitive Information to an Unauthorized Actor, Race Condition
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could compromise the confidentiality, integri
BSD
FreeBSD-SA-16:24.ntp: Multiple vulnerabilities of ntp
bsd_advisories·2016-06-04·CVSS 7.5
CVE-2016-4953 [HIGH] FreeBSD-SA-16:24.ntp: Multiple vulnerabilities of ntp
FreeBSD-SA-16:24.ntp Security Advisory
The FreeBSD Project
Topic: Multiple vulnerabilities of ntp
Category: contrib
Module: ntp
Announced: 2016-06-04
Credits: Network Time Foundation and various contributors listed below
Affects: All supported versions of FreeBSD.
Corrected: 2016-06-03 08:59:21 UTC (stable/10, 10.3-STABLE)
2016-06-04 05:46:52 UTC (releng/10.3, 10.3-RELEASE-p5)
2016-06-04 05:46:52 UTC (releng/10.2, 10.2-RELEASE-p19)
2016-06-04 05:46:52 UTC (releng/10.1, 10.1-RELEASE-p36)
2016-06-03 09:03:10 UTC (stable/9, 9.3-STABLE)
2016-06-04 05:46:52 UTC (releng/9.3, 9.3-RELEASE-p44)
CVE Name: CVE-2016-4957, CVE-2016-4953, CVE-2016-4954, CVE-2016-4955
CVE-2016-4956
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branc
Cisco
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016
vendor_cisco·2016-06-03
CVE-2016-4953 [HIGH] Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016
Multiple Cisco products incorporate a version of the Network Time Protocol daemon (ntpd) package. Versions of this package are affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or modify the time being advertised by a device acting as a Network Time Protocol (NTP) server.
On June 2, 2016, the NTP Consortium of the Network Time Foundation released a security notice that details five issues regarding DoS vulnerabilities and logic issues that may allow an attacker to shift a system's time.
The new vulnerabilities disclosed in this document are as follows:
Network Time Protocol CRYPTO-NAK Denial of Service Vuln
Red Hat
ntp: bad authentication demobilizes ephemeral associations
vendor_redhat·2016-06-02·CVSS 7.5
CVE-2016-4953 [HIGH] ntp: bad authentication demobilizes ephemeral associations
ntp: bad authentication demobilizes ephemeral associations
ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (ephemeral-association demobilization) by sending a spoofed crypto-NAK packet with incorrect authentication data at a certain time.
Statement: This issue did not affect the versions of ntp as shipped with any Red Hat Enterprise Linux version as they already included a fix for this issue in the patch provided to fix the CVE-2015-7979 issue. The fix for this issue (developed by Red Hat) was different from the one provided by upstream, and thus ntp versions in RHEL are not affected by CVE-2016-4953.
Package: ntp (Red Hat Enterprise Linux 5) - Not affected
Package: ntp (Red Hat Enterprise Linux 6) - Not affected
Package: ntp (Red Hat Enterprise Lin
Debian
CVE-2016-4953: ntp - ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of serv...
vendor_debian·2016·CVSS 7.5
CVE-2016-4953 [HIGH] CVE-2016-4953: ntp - ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of serv...
ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (ephemeral-association demobilization) by sending a spoofed crypto-NAK packet with incorrect authentication data at a certain time.
Scope: local
bullseye: resolved (fixed in 1:4.2.8p8+dfsg-1)
Cisco
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016
vendor_cisco
CVE-2016-4953 Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016
CVE-2016-4953: Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016
Multiple Cisco products incorporate a version of the Network Time Protocol daemon (ntpd) package. Versions of this package are affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or modify the time being advertised by a device acting as a Network Time Protocol (NTP) server. On June 2, 2016, the NTP Consortium of the Network Time Foundation released a security notice that
Bug IDs: CSCuz92606, CSCuz92609, CSCuz92629, CSCuz92606, CSCuz92609
No detection rules found.
No public exploits indexed.
http://bugs.ntp.org/3045http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00024.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00028.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00040.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00042.htmlhttp://packetstormsecurity.com/files/137321/Slackware-Security-Advisory-ntp-Updates.htmlhttp://packetstormsecurity.com/files/137322/FreeBSD-Security-Advisory-FreeBSD-SA-16-24.ntp.htmlhttp://support.ntp.org/bin/view/Main/NtpBug3045http://support.ntp.org/bin/view/Main/SecurityNoticehttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160603-ntpdhttp://www.kb.cert.org/vuls/id/321640http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/archive/1/538599/100/0/threadedhttp://www.securityfocus.com/archive/1/538600/100/0/threadedhttp://www.securityfocus.com/archive/1/540683/100/0/threadedhttp://www.securityfocus.com/archive/1/archive/1/538599/100/0/threadedhttp://www.securityfocus.com/archive/1/archive/1/538600/100/0/threadedhttp://www.securityfocus.com/archive/1/archive/1/540683/100/0/threadedhttp://www.securityfocus.com/bid/91010http://www.securitytracker.com/id/1036037https://cert-portal.siemens.com/productcert/pdf/ssa-211752.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-497656.pdfhttps://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03757en_ushttps://security.FreeBSD.org/advisories/FreeBSD-SA-16:24.ntp.aschttps://security.gentoo.org/glsa/201607-15https://us-cert.cisa.gov/ics/advisories/icsa-21-103-11https://us-cert.cisa.gov/ics/advisories/icsa-21-159-11https://www.kb.cert.org/vuls/id/321640http://bugs.ntp.org/3045http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00024.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00028.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00040.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00042.htmlhttp://packetstormsecurity.com/files/137321/Slackware-Security-Advisory-ntp-Updates.htmlhttp://packetstormsecurity.com/files/137322/FreeBSD-Security-Advisory-FreeBSD-SA-16-24.ntp.htmlhttp://support.ntp.org/bin/view/Main/NtpBug3045http://support.ntp.org/bin/view/Main/SecurityNoticehttp://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160603-ntpdhttp://www.kb.cert.org/vuls/id/321640http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/archive/1/538599/100/0/threadedhttp://www.securityfocus.com/archive/1/538600/100/0/threadedhttp://www.securityfocus.com/archive/1/540683/100/0/threadedhttp://www.securityfocus.com/archive/1/archive/1/538599/100/0/threadedhttp://www.securityfocus.com/archive/1/archive/1/538600/100/0/threadedhttp://www.securityfocus.com/archive/1/archive/1/540683/100/0/threadedhttp://www.securityfocus.com/bid/91010http://www.securitytracker.com/id/1036037https://cert-portal.siemens.com/productcert/pdf/ssa-211752.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-497656.pdfhttps://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03757en_ushttps://security.FreeBSD.org/advisories/FreeBSD-SA-16:24.ntp.aschttps://security.gentoo.org/glsa/201607-15https://us-cert.cisa.gov/ics/advisories/icsa-21-103-11https://us-cert.cisa.gov/ics/advisories/icsa-21-159-11https://www.kb.cert.org/vuls/id/321640
2016-07-05
Published