CVE-2015-7974
NTP 4.x before 4.2.8p6 and 4.3.x before 4.3.90 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via an arbitrary trusted key, aka a "skeleton key."
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.66%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
NTP 4.x before 4.2.8p6 and 4.3.x before 4.3.90 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via an arbitrary trusted key, aka a "skeleton key."
- CVSS 3.1
- 7.7 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
- EPSS
- 5.66% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- ntp/ntp · siemens/tim 4r-ie firmware · siemens/tim 4r-ie dnp3 firmware · netapp/clustered data ontap · netapp/oncommand balance · debian/debian linux
- Source
- cve@mitre.org
References
- http://bugs.ntp.org/show_bug.cgi?id=2936Issue Tracking, Vendor Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2583.htmlThird Party Advisory
- http://support.ntp.org/bin/view/Main/NtpBug2936Vendor Advisory
- http://www.debian.org/security/2016/dsa-3629Third Party Advisory
- http://www.securityfocus.com/bid/81960Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1034782Third Party Advisory, VDB Entry
- http://www.talosintel.com/reports/TALOS-2016-0071/Exploit, Third Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-497656.pdfThird Party Advisory
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03750en_usThird Party Advisory
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03766en_usThird Party Advisory
- https://security.FreeBSD.org/advisories/FreeBSD-SA-16:09.ntp.ascThird Party Advisory
- https://security.gentoo.org/glsa/201607-15Third Party Advisory
- https://security.netapp.com/advisory/ntap-20171031-0001/Third Party Advisory
- https://us-cert.cisa.gov/ics/advisories/icsa-21-103-11Third Party Advisory, US Government Resource
- http://bugs.ntp.org/show_bug.cgi?id=2936Issue Tracking, Vendor Advisory
- http://rhn.redhat.com/errata/RHSA-2016-2583.htmlThird Party Advisory
- http://support.ntp.org/bin/view/Main/NtpBug2936Vendor Advisory
- http://www.debian.org/security/2016/dsa-3629Third Party Advisory
- http://www.securityfocus.com/bid/81960Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1034782Third Party Advisory, VDB Entry
- http://www.talosintel.com/reports/TALOS-2016-0071/Exploit, Third Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-497656.pdfThird Party Advisory
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03750en_usThird Party Advisory
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03766en_usThird Party Advisory
- https://security.FreeBSD.org/advisories/FreeBSD-SA-16:09.ntp.ascThird Party Advisory
- https://security.gentoo.org/glsa/201607-15Third Party Advisory
- https://security.netapp.com/advisory/ntap-20171031-0001/Third Party Advisory
- https://us-cert.cisa.gov/ics/advisories/icsa-21-103-11Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.