Junglewise Threat Intelligence

CVE-2015-8140: NTP ntpq protocol replay attack vulnerability

CVE-2015-8140 · Severity: medium · CVSS 4.8 · Published 2017-01-30

Executive brief

A vulnerability in the Network Time Protocol (NTP) utility could allow an attacker to intercept and resend network traffic. This could potentially be used to disrupt time synchronization services or manipulate system logs. Organizations relying on precise timekeeping for security or operational logging should ensure their systems are updated.

Technical details

The ntpq protocol in NTP versions prior to 4.2.8p7 is vulnerable to replay attacks. An attacker with the ability to sniff network traffic can capture legitimate ntpq control packets and re-transmit them to the target server. This occurs due to improper access control and lack of sufficient replay protection within the ntpq protocol implementation. Successful exploitation could allow an attacker to perform unauthorized configuration queries or minor modifications, potentially impacting the integrity and availability of the time service. The issue is addressed in NTP 4.2.8p7.

Affected products

  • NTP Project NTP Before 4.2.8p7

Timeline

  • 2016-01-27: advisory: Cisco security advisory published
  • 2017-01-30: disclosed: NVD publication date

References

Related threats