Lucene search

K
f5F5F5:K13304944
HistoryFeb 23, 2016 - 12:00 a.m.

K13304944 : NTP vulnerability CVE-2015-7974

2016-02-2300:00:00
my.f5.com
22

AI Score

7.5

Confidence

High

EPSS

0.003

Percentile

69.2%

Security Advisory Description

NTP 4.x before 4.2.8p6 and 4.3.x before 4.3.90 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via an arbitrary trusted key, aka a “skeleton key.” (CVE-2015-7974)
Impact
When multiple network time protocol (NTP) servers are configured using symmetric key authentication, one server could potentially spoof another server using its own key.