PT-2016-6189 · Ntf+5 · Ntp+5
Miroslav Lichvar
·
Publicado
2016-06-03
·
Atualizado
2024-06-15
·
CVE-2016-4956
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
NTP versions prior to 4.2.8p8
Description
The issue allows remote attackers to cause a denial of service or modify the time being advertised by a device acting as a Network Time Protocol server via a spoofed broadcast packet. This is due to an incomplete fix for a previous issue. Multiple vulnerabilities exist, including Network Time Protocol CRYPTO-NAK Denial of Service, Network Time Protocol Bad Authentication, Network Time Protocol Processing Spoofed Server Packets, Network Time Protocol Autokey Association Reset, and Network Time Protocol Broadcast Interleave.
Recommendations
For versions prior to 4.2.8p8, update to version 4.2.8p8 or later to resolve the issue. As a temporary workaround, consider restricting access to the
ntpd package to minimize the risk of exploitation. Additionally, workarounds may be available and documented in the Cisco bug for each affected product.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Cisco Ios
Freebsd
Ntp
Suse
Ubuntu