PT-2018-4260 · Ntt+1 · Ntp+1
Published
2018-08-14
·
Updated
2020-01-24
·
CVE-2014-5209
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
NTP version 4.2.7p25
Description
The issue allows a malicious user to obtain sensitive information through private (mode 6/7) messages via a GET RESTRICT control message. Additionally, a remote authenticated attacker could bypass security restrictions by creating multiple ephemeral associations to win the clock selection of ntpd, potentially modifying a victim's clock.
Recommendations
For NTP version 4.2.7p25, consider restricting access to the GET RESTRICT control message to prevent information disclosure. As a temporary workaround, restrict the ability to create multiple ephemeral associations to prevent Sybil attacks from authenticated peers.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Aix
Ntp