Junglewise Threat Intelligence

CVE-2015-8139: NTP ntpq origin timestamp leak and peer impersonation

CVE-2015-8139 · Severity: medium · CVSS 5.3 · Published 2017-01-30

Executive brief

A vulnerability in the Network Time Protocol (NTP) software could allow an attacker to impersonate a trusted time server. NTP is a critical service used to synchronize clocks across computers and network devices. By exploiting this flaw, an attacker could potentially provide false time information to a system, which can disrupt security logs, scheduled tasks, and authentication mechanisms.

Technical details

A vulnerability exists in the ntpq and ntpdc utilities within NTP versions prior to 4.2.8p7 due to improper access control. The software discloses origin timestamps to unauthenticated remote clients, which are intended to be private values used to validate legitimate time responses. An attacker can capture these leaked timestamps and use them to craft spoofed NTP packets that appear to come from a trusted peer. This allows for the injection of false time data into the target system. The issue is addressed in NTP 4.2.8p7.

Affected products

  • NTP Project NTP before 4.2.8p7

Timeline

  • 2016-01-27: advisory: Cisco security advisory published
  • 2017-01-30: disclosed: NVD publication date

References

Related threats