VulnerabilityModified
CVE-2016-1384
The NTP implementation in Cisco IOS 15.1 and 15.5 and IOS XE 3.2 through 3.17 allows remote attackers to modify the system time via crafted packets, aka Bug ID CSCux46898.
HIGH 7.5EPSS 2.49%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.49%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The NTP implementation in Cisco IOS 15.1 and 15.5 and IOS XE 3.2 through 3.17 allows remote attackers to modify the system time via crafted packets, aka Bug ID CSCux46898.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 2.49% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- cisco/ios · cisco/ios xe
- Source
- psirt@cisco.com
References
- http://www.securityfocus.com/bid/86685
- http://www.securitytracker.com/id/1035622
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160419-iosVendor Advisory
- http://www.securityfocus.com/bid/86685
- http://www.securitytracker.com/id/1035622
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160419-iosVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.