Lucene search

K
ciscoCiscoCISCO-SA-20160603-NTPD
HistoryJun 03, 2016 - 4:00 p.m.

Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016

2016-06-0316:00:00
tools.cisco.com
27

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.923 High

EPSS

Percentile

99.0%

Multiple Cisco products incorporate a version of the Network Time Protocol daemon (ntpd) package. Versions of this package are affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or modify the time being advertised by a device acting as a Network Time Protocol (NTP) server.

On June 2, 2016, the NTP Consortium of the Network Time Foundation released a security notice that details five issues regarding DoS vulnerabilities and logic issues that may allow an attacker to shift a system’s time.

The new vulnerabilities disclosed in this document are as follows:

Network Time Protocol CRYPTO-NAK Denial of Service Vulnerability
Network Time Protocol Bad Authentication Demobilizes Ephemeral Associations Vulnerability
Network Time Protocol Processing Spoofed Server Packets Vulnerability
Network Time Protocol Autokey Association Reset Vulnerability
Network Time Protocol Broadcast Interleave Vulnerability
Additional details about each vulnerability are in the NTP Consortium Security Notice [“http://support.ntp.org/bin/view/Main/SecurityNotice#April_2016_NTP_4_2_8p7_Security”].

Cisco will release software updates that address these vulnerabilities.

Workarounds that address one or more of these vulnerabilities may be available and will be documented in the Cisco bug for each affected product.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160603-ntpd [“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160603-ntpd”]

Affected configurations

Vulners
Node
ciscoapplication_and_content_networking_system_softwareMatchany
OR
ciscoemergency_responderMatchany
OR
ciscoios_xr_softwareMatchany
OR
ciscounity_expressMatchany
OR
cisconac_applianceMatchany
OR
ciscointrusion_prevention_systemMatchany
OR
ciscoace_application_control_engine_module_a3Matchany
OR
ciscowide_area_application_servicesMatchany
OR
ciscounified_meetingplaceMatchany
OR
ciscoip_interoperability_and_collaboration_systemMatchany
OR
ciscounity_connectionMatchany
OR
ciscotelepresence_mx200Matchany
OR
ciscophysical_access_gatewayMatchany
OR
ciscocisco_iosMatchanyxe
OR
ciscovideo_surveillance_media_serverMatchany
OR
ciscodigital_media_managerMatchany
OR
cisconetwork_analysis_module_softwareMatchany
OR
ciscoironport_encryption_applianceMatchany
OR
cisconetwork_admission_controlMatchany
OR
ciscoshow_and_shareMatchany
OR
ciscoidentity_services_engine_softwareMatchany
OR
ciscotelepresence_video_communication_serverMatchany
OR
ciscoasa_cx_context-aware_security_softwareMatchany
OR
ciscoprime_security_managerMatchany
OR
ciscoprime_data_center_network_managerMatchany
OR
ciscoprime_lan_management_solutionMatchany
OR
ciscounified_communications_domain_managerMatchany
OR
ciscoprime_infrastructureMatchany
OR
ciscoconnected_grid_network_management_systemMatchany
OR
ciscowebex_meetings_serverMatchany
OR
ciscowebex_node_for_mcsMatchany
OR
ciscounified_computing_system_central_softwareMatchany
OR
ciscoenterprise_content_delivery_systemMatchany
OR
ciscovirtualization_experience_media_engineMatchany
OR
ciscomediasenseMatchany
OR
ciscounified_sip_proxyMatchany
OR
ciscoucs_directorMatchany
OR
ciscovideoscape_distribution_suite_service_brokerMatchany
OR
ciscodigital_content_managerMatchany
OR
ciscoprime_service_catalogMatchany
OR
cisconexus_1000vMatchanynexus_1000v
OR
ciscoapplication_policy_infrastructure_controller_\(apic\)Matchany
OR
ciscoexpresswayMatchany
OR
ciscojabber_guestMatchany
OR
ciscodesktop_collaboration_experienceMatchany
OR
ciscoprime_license_managerMatchany
OR
ciscongips_virtual_applianceMatchany
OR
ciscoprime_network_services_controllerMatchany
OR
ciscotelepresence_isdn_gw_3241Matchany
OR
ciscotelepresence_conductorMatchany
OR
ciscofirepower_system_softwareMatchany
OR
ciscoprime_collaboration_assuranceMatchany
OR
ciscoprime_collaboration_provisioningMatchany
OR
ciscopaging_serverMatchany
OR
ciscomodular_encoding_platform_d9036_softwareMatchany
OR
ciscovideoscape_distribution_suite_service_brokerMatchany
OR
ciscovirtual_topology_systemMatchany
OR
cisconexus_3000Matchany
OR
ciscocisco_policy_suiteMatchany
OR
ciscohosted_collaboration_mediation_fulfillmentMatchany
OR
ciscocloud_services_platform_2100Matchany
OR
ciscoregistered_envelope_serviceMatchany
OR
ciscoapplication_and_content_networking_system_softwareMatchany
OR
ciscoemergency_responderMatchany
OR
ciscoios_xr_softwareMatchany
OR
ciscounity_expressMatchany
OR
cisconac_applianceMatchany
OR
ciscointrusion_prevention_systemMatchany
OR
ciscoace_application_control_engine_module_a3Matchany
OR
ciscowide_area_application_servicesMatchany
OR
ciscounified_meetingplaceMatchany
OR
ciscoip_interoperability_and_collaboration_systemMatchany
OR
ciscounity_connectionMatchany
OR
ciscotelepresence_mx200Matchany
OR
ciscophysical_access_gatewayMatchany
OR
ciscocisco_iosMatchanyxe
OR
ciscovideo_surveillance_media_serverMatchany
OR
ciscodigital_media_managerMatchany
OR
cisconetwork_analysis_module_softwareMatchany
OR
ciscoironport_encryption_applianceMatchany
OR
cisconetwork_admission_controlMatchany
OR
ciscoshow_and_shareMatchany
OR
ciscoidentity_services_engine_softwareMatchany
OR
ciscotelepresence_video_communication_serverMatchany
OR
ciscoasa_cx_context-aware_security_softwareMatchany
OR
ciscoprime_security_managerMatchany
OR
ciscoprime_data_center_network_managerMatchany
OR
ciscoprime_lan_management_solutionMatchany
OR
ciscounified_communications_domain_managerMatchany
OR
ciscoprime_infrastructureMatchany
OR
ciscoconnected_grid_network_management_systemMatchany
OR
ciscowebex_meetings_serverMatchany
OR
ciscowebex_node_for_mcsMatchany
OR
ciscounified_computing_system_central_softwareMatchany
OR
ciscoenterprise_content_delivery_systemMatchany
OR
ciscovirtualization_experience_media_engineMatchany
OR
ciscomediasenseMatchany
OR
ciscounified_sip_proxyMatchany
OR
ciscoucs_directorMatchany
OR
ciscovideoscape_distribution_suite_service_brokerMatchany
OR
ciscodigital_content_managerMatchany
OR
ciscoprime_service_catalogMatchany
OR
cisconexus_1000vMatch1000v_switchnexus_1000v
OR
ciscoapplication_policy_infrastructure_controller_\(apic\)Matchany
OR
ciscoexpresswayMatchany
OR
ciscojabber_guestMatchany
OR
ciscodesktop_collaboration_experienceMatchany
OR
ciscoprime_license_managerMatchany
OR
ciscongips_virtual_applianceMatchany
OR
ciscoprime_network_services_controllerMatchany
OR
ciscotelepresence_isdn_gw_3241Matchany
OR
ciscotelepresence_conductorMatchany
OR
ciscofirepower_system_softwareMatchany
OR
ciscoprime_collaboration_assuranceMatchany
OR
ciscoprime_collaboration_provisioningMatchany
OR
ciscopaging_serverMatchany
OR
ciscomodular_encoding_platform_d9036_softwareMatchany
OR
ciscovideoscape_distribution_suite_service_brokerMatchany
OR
ciscovirtual_topology_systemMatchany
OR
cisconexus_1000vMatch3000_series_switchnexus_1000v
OR
ciscocisco_policy_suiteMatchany
OR
ciscohosted_collaboration_mediation_fulfillmentMatchany
OR
ciscocloud_services_platform_2100Match2100
OR
ciscoregistered_envelope_serviceMatchany

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.923 High

EPSS

Percentile

99.0%