Vulnslist

find the latest Cisco vulnerabilities

Network Time Protocol Daemon Symmetric Mode Packet Processing Denial of Service Vulnerability

Cisco-SA-20150408-CVE-2015-1799 · Medium · Published · Updated

A vulnerability in ntpd could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected system. The vulnerability is due to improper processing of Network Time Protocol (NTP) packets when handling symmetric key authentication failures. An attacker could exploit this vulnerability by conducting a man-in-the-middle attack to periodically transmit crafted NTP packets with set NTP state variables. An exploit could allow the attacker to disrupt communication between NTP hosts, preventing synchronization and leading to a DoS condition for legitimate users. NTP.org has confirmed this vulnerability in a security advisory and released software updates. To exploit this vulnerability, an attacker may require access to trusted, internal networks to send crafted requests to the affected software. This access requirement could limit the likelihood of a successful exploit. An attacker may attempt to perform a man-in-the-middle attack to send crafted packets to the targeted device in an attempt to exploit this vulnerability. Reports indicate that systems that are configured to use the symmetric key authentication mechanism are affected.

Cisco advisory · CSAF JSON

Workarounds

Administrators are advised to apply the appropriate updates.

Administrators are advised to allow only privileged users to access administration or management systems.

Administrators are advised to implement an intrusion prevention system (IPS) or intrusion detection system (IDS) to help detect and prevent attacks that attempt to exploit this vulnerability.

The Cisco Applied Intelligence team has created the following companion document to guide administrators in identifying and mitigating attempts to exploit this vulnerability prior to applying updated software: Identifying and Mitigating Multiple Vulnerabilities in Network Time Protocol["http://tools.cisco.com/security/center/viewAMBAlert.x?alertId=36857"]

CVEsCVE-2015-1799
Cisco Bug IDsCSCut77471
CVSS ScoreBase 4.3
Base 4.3 AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C
Product Names From Source
Cisco Unified Computing System Central Software

Related Products

Product CVE Evidence
Cisco Unified Computing System Central Software CVE-2015-1799 Cisco OpenVuln