Lucene search

K
ciscoCiscoCISCO-SA-20141222-NTPD
HistoryDec 22, 2014 - 4:00 p.m.

Multiple Vulnerabilities in ntpd Affecting Cisco Products

2014-12-2216:00:00
tools.cisco.com
30

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

0.966 High

EPSS

Percentile

99.6%

Multiple Cisco products incorporate a version of the ntpd package. Versions of this package are affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to execute arbitrary code or create a denial of service (DoS) condition.

On December 19, 2014, NTP.org and US-CERT released security advisories detailing two issues regarding weak cryptographic pseudorandom number generation (PRNG), three buffer overflow vulnerabilities, and an unhandled error condition with an unknown impact. These vulnerabilities are referenced in this document as follows:

CVE-2014-9293: Weak Default Key in config_auth()
CVE-2014-9294: Noncryptographic Random Number Generator with Weak Seed Used by ntp-keygen to Generate Symmetric Keys
CVE-2014-9295: Multiple Buffer Overflow Vulnerabilities in ntpd
CVE-2014-9296: ntpd receive(): Missing Return on Error
On February 4, 2015, NTP.org and US-CERT released two additional vulnerabilities regarding improper validation of vallen in ntp_crypto.c and an IPv6 ::1 ACL bypass vulnerability. These vulnerabilities were added to their original advisory. For completeness, these vulnerabilities are referenced in this document as follows:

CVE-2014-9297: NTP ntp_crypto.c Improper Validation Vulnerability
CVE-2014-9298: NTP IPv6 ACL Bypass Vulnerability
This advisory will be updated as additional information becomes available.

Cisco will release software updates that address these vulnerabilities.

Workarounds that mitigate these vulnerabilities are available.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20141222-ntpd [“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20141222-ntpd”]

Affected configurations

Vulners
Node
ciscoapplication_and_content_networking_system_softwareMatchany
OR
ciscoemergency_responderMatchany
OR
ciscoios_xr_softwareMatchany
OR
cisconac_applianceMatchany
OR
ciscounified_presence_serverMatchany
OR
ciscowide_area_application_servicesMatchany
OR
ciscounified_contact_center_enterpriseMatchany
OR
ciscoip_interoperability_and_collaboration_systemMatchany
OR
ciscoservice_control_engineMatchany
OR
cisconx_osMatch4.1
OR
cisconx_osMatch5.0
OR
cisconx_osMatch4.2
OR
cisconx_osMatch5.1
OR
cisconx_osMatch5.2
OR
cisconx_osMatch6.1
OR
cisconx_osMatch4.0\(0\)n1
OR
cisconx_osMatch4.0\(1a\)n1
OR
cisconx_osMatch4.0\(1a\)n2
OR
cisconx_osMatch4.1\(2\)e1
OR
cisconx_osMatch4.1\(3\)n1
OR
cisconx_osMatch4.1\(3\)n2
OR
cisconx_osMatch4.2\(1\)n1
OR
cisconx_osMatch4.2\(1\)n2
OR
cisconx_osMatch4.2\(1\)sv1
OR
cisconx_osMatch4.2\(1\)sv2
OR
cisconx_osMatch5.0\(2\)n1
OR
cisconx_osMatch5.0\(2\)n2
OR
cisconx_osMatch5.0\(3\)n1
OR
cisconx_osMatch5.0\(3\)n2
OR
cisconx_osMatch5.0\(3\)u1
OR
cisconx_osMatch5.0\(3\)u2
OR
cisconx_osMatch5.0\(3\)u3
OR
cisconx_osMatch5.0\(3\)u4
OR
cisconx_osMatch5.0\(3\)u5
OR
cisconx_osMatch5.1\(3\)n1
OR
cisconx_osMatch5.1\(3\)n2
OR
cisconx_osMatch5.2\(1\)n1
OR
cisconx_osMatch5.2\(1\)sm1
OR
cisconx_osMatch6.0
OR
cisconx_osMatch6.0\(2\)n1
OR
cisconx_osMatch6.0\(2\)n2
OR
cisconx_osMatch6.0\(2\)u1
OR
cisconx_osMatch6.0\(2\)u2
OR
cisconx_osMatch6.0\(2\)u3
OR
cisconx_osMatch6.0\(2\)u4
OR
cisconx_osMatch6.0\(2\)u5
OR
cisconx_osMatch6.1\(2\)i2
OR
cisconx_osMatch6.1\(2\)i3
OR
cisconx_osMatch6.2
OR
cisconx_osMatch7.0\(0\)n1
OR
cisconx_osMatch7.0\(1\)n1
OR
cisconx_osMatch7.0\(2\)n1
OR
cisconx_osMatch7.0\(3\)n1
OR
ciscounified_communications_managerMatchany
OR
ciscoapplication_networking_managerMatchany
OR
ciscounified_provisioning_managerMatchany
OR
ciscophysical_access_gatewayMatchany
OR
ciscovideo_surveillance_media_serverMatchany
OR
ciscodigital_media_managerMatchany
OR
ciscoip_interoperability_and_collaboration_systemMatchany
OR
ciscoironport_encryption_applianceMatchany
OR
cisconetwork_admission_controlMatchany
OR
ciscotelepresence_mxp_softwareMatchany
OR
ciscoshow_and_shareMatchany
OR
cisconexus_1000vMatchanynexus_1000v
OR
ciscotelepresence_managerMatchany
OR
ciscoasa_cx_context-aware_security_softwareMatchany
OR
ciscoprime_security_managerMatchany
OR
ciscoprime_data_center_network_managerMatchany
OR
ciscoprime_infrastructureMatchany
OR
ciscowebex_meetings_serverMatchany
OR
ciscotelepresence_system_softwareMatchany
OR
ciscoenterprise_content_delivery_systemMatchany
OR
ciscotelepresence_tc_softwareMatchany
OR
ciscotelepresence_te_softwareMatchany
OR
ciscovirtualization_experience_client_6000_series_firmwareMatchany
OR
ciscofinesseMatchany
OR
ciscosocialminerMatchany
OR
ciscomediasenseMatchany
OR
ciscomedia_experience_engine_5600Matchany
OR
ciscoucs_directorMatchany
OR
ciscodigital_content_managerMatchany
OR
ciscounified_intelligence_centerMatchany
OR
ciscoprime_service_catalogMatchany
OR
ciscoapplication_policy_infrastructure_controller_\(apic\)Matchany
OR
cisco300_series_managed_switchesMatchany
OR
ciscojabber_guestMatchany
OR
ciscounified_computing_system_softwareMatchany
OR
ciscoprime_license_managerMatchany
OR
ciscointersight_virtual_applianceMatchany
OR
ciscotelepresence_isdn_gw_3241Matchany
OR
ciscomodular_encoding_platform_d9036_softwareMatchany
OR
ciscofirepower_system_softwareMatchany
OR
ciscoapplication_and_content_networking_system_softwareMatchany
OR
ciscoemergency_responderMatchany
OR
ciscoios_xr_softwareMatchany
OR
cisconac_applianceMatchany
OR
ciscounified_presence_serverMatchany
OR
ciscowide_area_application_servicesMatchany
OR
ciscounified_contact_center_enterpriseMatchany
OR
ciscoip_interoperability_and_collaboration_systemMatchany
OR
ciscoservice_control_engineMatchany
OR
cisconx_osMatch4.1\(2\)
OR
cisconx_osMatch4.1\(3\)
OR
cisconx_osMatch4.1\(4\)
OR
cisconx_osMatch4.1\(5\)
OR
cisconx_osMatch5.0\(2a\)
OR
cisconx_osMatch5.0\(3\)
OR
cisconx_osMatch5.0\(5\)
OR
cisconx_osMatch4.2\(2a\)
OR
cisconx_osMatch4.2\(3\)
OR
cisconx_osMatch4.2\(4\)
OR
cisconx_osMatch4.2\(6\)
OR
cisconx_osMatch4.2\(8\)
OR
cisconx_osMatch5.1\(1\)
OR
cisconx_osMatch5.1\(1a\)
OR
cisconx_osMatch5.1\(3\)
OR
cisconx_osMatch5.1\(4\)
OR
cisconx_osMatch5.1\(5\)
OR
cisconx_osMatch5.1\(6\)
OR
cisconx_osMatch5.2\(1\)
OR
cisconx_osMatch5.2\(3a\)
OR
cisconx_osMatch5.2\(4\)
OR
cisconx_osMatch5.2\(5\)
OR
cisconx_osMatch5.2\(7\)
OR
cisconx_osMatch5.2\(9\)
OR
cisconx_osMatch6.1\(1\)
OR
cisconx_osMatch6.1\(2\)
OR
cisconx_osMatch6.1\(3\)
OR
cisconx_osMatch6.1\(4\)
OR
cisconx_osMatch6.1\(4a\)
OR
cisconx_osMatch4.0\(0\)n1\(1a\)
OR
cisconx_osMatch4.0\(0\)n1\(2\)
OR
cisconx_osMatch4.0\(0\)n1\(2a\)
OR
cisconx_osMatch4.0\(1a\)n1\(1\)
OR
cisconx_osMatch4.0\(1a\)n1\(1a\)
OR
cisconx_osMatch4.0\(1a\)n2\(1\)
OR
cisconx_osMatch4.0\(1a\)n2\(1a\)
OR
cisconx_osMatch4.1\(2\)e1\(1\)
OR
cisconx_osMatch4.1\(2\)e1\(1b\)
OR
cisconx_osMatch4.1\(2\)e1\(1d\)
OR
cisconx_osMatch4.1\(2\)e1\(1e\)
OR
cisconx_osMatch4.1\(2\)e1\(1f\)
OR
cisconx_osMatch4.1\(2\)e1\(1g\)
OR
cisconx_osMatch4.1\(2\)e1\(1h\)
OR
cisconx_osMatch4.1\(2\)e1\(1i\)
OR
cisconx_osMatch4.1\(2\)e1\(1j\)
OR
cisconx_osMatch4.1\(3\)n1\(1\)
OR
cisconx_osMatch4.1\(3\)n1\(1a\)
OR
cisconx_osMatch4.1\(3\)n2\(1\)
OR
cisconx_osMatch4.1\(3\)n2\(1a\)
OR
cisconx_osMatch4.2\(1\)n1\(1\)
OR
cisconx_osMatch4.2\(1\)n2\(1\)
OR
cisconx_osMatch4.2\(1\)n2\(1a\)
OR
cisconx_osMatch4.2\(1\)sv1\(4\)
OR
cisconx_osMatch4.2\(1\)sv1\(4a\)
OR
cisconx_osMatch4.2\(1\)sv1\(4b\)
OR
cisconx_osMatch4.2\(1\)sv1\(5.1\)
OR
cisconx_osMatch4.2\(1\)sv1\(5.1a\)
OR
cisconx_osMatch4.2\(1\)sv1\(5.2\)
OR
cisconx_osMatch4.2\(1\)sv1\(5.2b\)
OR
cisconx_osMatch4.2\(1\)sv2\(1.1\)
OR
cisconx_osMatch4.2\(1\)sv2\(1.1a\)
OR
cisconx_osMatch4.2\(1\)sv2\(2.1\)
OR
cisconx_osMatch4.2\(1\)sv2\(2.1a\)
OR
cisconx_osMatch5.0\(2\)n1\(1\)
OR
cisconx_osMatch5.0\(2\)n2\(1\)
OR
cisconx_osMatch5.0\(2\)n2\(1a\)
OR
cisconx_osMatch5.0\(3\)n1\(1c\)
OR
cisconx_osMatch5.0\(3\)n2\(1\)
OR
cisconx_osMatch5.0\(3\)n2\(2\)
OR
cisconx_osMatch5.0\(3\)n2\(2a\)
OR
cisconx_osMatch5.0\(3\)n2\(2b\)
OR
cisconx_osMatch5.0\(3\)u1\(1\)
OR
cisconx_osMatch5.0\(3\)u1\(1a\)
OR
cisconx_osMatch5.0\(3\)u1\(1b\)
OR
cisconx_osMatch5.0\(3\)u1\(1d\)
OR
cisconx_osMatch5.0\(3\)u1\(2\)
OR
cisconx_osMatch5.0\(3\)u1\(2a\)
OR
cisconx_osMatch5.0\(3\)u2\(1\)
OR
cisconx_osMatch5.0\(3\)u2\(2\)
OR
cisconx_osMatch5.0\(3\)u2\(2a\)
OR
cisconx_osMatch5.0\(3\)u2\(2b\)
OR
cisconx_osMatch5.0\(3\)u2\(2c\)
OR
cisconx_osMatch5.0\(3\)u2\(2d\)
OR
cisconx_osMatch5.0\(3\)u3\(1\)
OR
cisconx_osMatch5.0\(3\)u3\(2\)
OR
cisconx_osMatch5.0\(3\)u3\(2a\)
OR
cisconx_osMatch5.0\(3\)u3\(2b\)
OR
cisconx_osMatch5.0\(3\)u4\(1\)
OR
cisconx_osMatch5.0\(3\)u5\(1\)
OR
cisconx_osMatch5.0\(3\)u5\(1a\)
OR
cisconx_osMatch5.0\(3\)u5\(1b\)
OR
cisconx_osMatch5.0\(3\)u5\(1c\)
OR
cisconx_osMatch5.0\(3\)u5\(1d\)
OR
cisconx_osMatch5.0\(3\)u5\(1e\)
OR
cisconx_osMatch5.0\(3\)u5\(1f\)
OR
cisconx_osMatch5.0\(3\)u5\(1g\)
OR
cisconx_osMatch5.0\(3\)u5\(1h\)
OR
cisconx_osMatch5.1\(3\)n1\(1\)
OR
cisconx_osMatch5.1\(3\)n1\(1a\)
OR
cisconx_osMatch5.1\(3\)n2\(1\)
OR
cisconx_osMatch5.1\(3\)n2\(1a\)
OR
cisconx_osMatch5.1\(3\)n2\(1b\)
OR
cisconx_osMatch5.1\(3\)n2\(1c\)
OR
cisconx_osMatch5.2\(1\)n1\(1\)
OR
cisconx_osMatch5.2\(1\)n1\(1a\)
OR
cisconx_osMatch5.2\(1\)n1\(1b\)
OR
cisconx_osMatch5.2\(1\)n1\(2\)
OR
cisconx_osMatch5.2\(1\)n1\(2a\)
OR
cisconx_osMatch5.2\(1\)n1\(3\)
OR
cisconx_osMatch5.2\(1\)n1\(4\)
OR
cisconx_osMatch5.2\(1\)n1\(5\)
OR
cisconx_osMatch5.2\(1\)n1\(6\)
OR
cisconx_osMatch5.2\(1\)n1\(7\)
OR
cisconx_osMatch5.2\(1\)n1\(8a\)
OR
cisconx_osMatch5.2\(1\)n1\(8\)
OR
cisconx_osMatch5.2\(1\)sm1\(5.1\)
OR
cisconx_osMatch6.0\(1\)
OR
cisconx_osMatch6.0\(2\)
OR
cisconx_osMatch6.0\(3\)
OR
cisconx_osMatch6.0\(4\)
OR
cisconx_osMatch6.0\(2\)n1\(1\)
OR
cisconx_osMatch6.0\(2\)n1\(2\)
OR
cisconx_osMatch6.0\(2\)n1\(2a\)
OR
cisconx_osMatch6.0\(2\)n2\(1\)
OR
cisconx_osMatch6.0\(2\)n2\(1b\)
OR
cisconx_osMatch6.0\(2\)n2\(2\)
OR
cisconx_osMatch6.0\(2\)n2\(3\)
OR
cisconx_osMatch6.0\(2\)n2\(4\)
OR
cisconx_osMatch6.0\(2\)n2\(5\)
OR
cisconx_osMatch6.0\(2\)u1\(1\)
OR
cisconx_osMatch6.0\(2\)u1\(2\)
OR
cisconx_osMatch6.0\(2\)u1\(1a\)
OR
cisconx_osMatch6.0\(2\)u1\(3\)
OR
cisconx_osMatch6.0\(2\)u1\(4\)
OR
cisconx_osMatch6.0\(2\)u2\(1\)
OR
cisconx_osMatch6.0\(2\)u2\(2\)
OR
cisconx_osMatch6.0\(2\)u2\(3\)
OR
cisconx_osMatch6.0\(2\)u2\(4\)
OR
cisconx_osMatch6.0\(2\)u2\(5\)
OR
cisconx_osMatch6.0\(2\)u2\(6\)
OR
cisconx_osMatch6.0\(2\)u3\(1\)
OR
cisconx_osMatch6.0\(2\)u3\(2\)
OR
cisconx_osMatch6.0\(2\)u3\(3\)
OR
cisconx_osMatch6.0\(2\)u3\(4\)
OR
cisconx_osMatch6.0\(2\)u3\(5\)
OR
cisconx_osMatch6.0\(2\)u4\(1\)
OR
cisconx_osMatch6.0\(2\)u4\(2\)
OR
cisconx_osMatch6.0\(2\)u4\(3\)
OR
cisconx_osMatch6.0\(2\)u5\(1\)
OR
cisconx_osMatch6.1\(2\)i2\(1\)
OR
cisconx_osMatch6.1\(2\)i2\(2\)
OR
cisconx_osMatch6.1\(2\)i2\(2a\)
OR
cisconx_osMatch6.1\(2\)i2\(3\)
OR
cisconx_osMatch6.1\(2\)i2\(2b\)
OR
cisconx_osMatch6.1\(2\)i3\(3\)
OR
cisconx_osMatch6.2\(2\)
OR
cisconx_osMatch6.2\(2a\)
OR
cisconx_osMatch6.2\(6\)
OR
cisconx_osMatch7.0\(0\)n1\(1\)
OR
cisconx_osMatch7.0\(1\)n1\(1\)
OR
cisconx_osMatch7.0\(2\)n1\(1\)
OR
cisconx_osMatch7.0\(3\)n1\(1\)
OR
ciscounified_communications_managerMatchany
OR
ciscoapplication_networking_managerMatchany
OR
ciscounified_provisioning_managerMatchany
OR
ciscophysical_access_gatewayMatchany
OR
ciscovideo_surveillance_media_serverMatchany
OR
ciscodigital_media_managerMatchany
OR
ciscoip_interoperability_and_collaboration_systemMatchany
OR
ciscoironport_encryption_applianceMatchany
OR
cisconetwork_admission_controlMatchany
OR
ciscotelepresence_mxp_softwareMatchany
OR
ciscoshow_and_shareMatchany
OR
ciscoweb_security_virtual_applianceMatch1000v_series_switches
OR
ciscotelepresence_managerMatchany
OR
ciscoasa_cx_context-aware_security_softwareMatchany
OR
ciscoprime_security_managerMatchany
OR
ciscoprime_data_center_network_managerMatchany
OR
ciscoprime_infrastructureMatchany
OR
ciscowebex_meetings_serverMatchany
OR
ciscotelepresence_system_softwareMatchany
OR
ciscoenterprise_content_delivery_systemMatchany
OR
ciscotelepresence_tc_softwareMatchany
OR
ciscotelepresence_te_softwareMatchany
OR
ciscovirtualization_experience_client_6000Match6000_series_firmware
OR
ciscofinesseMatchany
OR
ciscosocialminerMatchany
OR
ciscomediasenseMatchany
OR
ciscocisco_mxeMatch3500_\(media_experience_engine\)
OR
ciscoucs_directorMatchany
OR
ciscodigital_content_managerMatchany
OR
ciscounified_intelligence_centerMatchany
OR
ciscoprime_service_catalogMatchany
OR
ciscoapplication_policy_infrastructure_controller_\(apic\)Matchany
OR
ciscoedge_340_firmwareMatch300_series
OR
ciscojabber_guestMatchany
OR
ciscounified_computing_system_softwareMatchany
OR
ciscoprime_license_managerMatchany
OR
ciscointersight_virtual_applianceMatchany
OR
ciscotelepresence_isdn_gw_3241Matchany
OR
ciscomodular_encoding_platform_d9036_softwareMatchany
OR
ciscofirepower_system_softwareMatchany

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

0.966 High

EPSS

Percentile

99.6%