CVE-2016-1567
chrony before 1.31.2 and 2.x before 2.2.1 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via an arbitrary trusted key, aka a "skeleton key."
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.62%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
chrony before 1.31.2 and 2.x before 2.2.1 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via an arbitrary trusted key, aka a "skeleton key."
- CVSS 3.0
- 8.1 HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.62% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-254
- Affected
- tuxfamily/chrony
- Source
- cve@mitre.org
References
- http://chrony.tuxfamily.org/news.html#_20_jan_2016_chrony_2_2_1_and_chrony_1_31_2_releasedVendor Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176559.html
- http://lists.fedoraproject.org/pipermail/package-announce/2016-January/175969.htmlPatch
- http://www.talosintel.com/reports/TALOS-2016-0071/Exploit
- http://chrony.tuxfamily.org/news.html#_20_jan_2016_chrony_2_2_1_and_chrony_1_31_2_releasedVendor Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176559.html
- http://lists.fedoraproject.org/pipermail/package-announce/2016-January/175969.htmlPatch
- http://www.talosintel.com/reports/TALOS-2016-0071/Exploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.