Executive brief
A vulnerability in the Network Time Protocol (NTP) utility could allow an attacker to intercept and resend network traffic. This could potentially be used to disrupt time synchronization services or manipulate system logs. Organizations relying on precise timekeeping for security or operational logging should ensure their systems are updated.
Technical details
The ntpq protocol in NTP versions prior to 4.2.8p7 is vulnerable to replay attacks. An attacker with the ability to sniff network traffic can capture legitimate ntpq control packets and re-transmit them to the target server. This occurs due to improper access control and lack of sufficient replay protection within the ntpq protocol implementation. Successful exploitation could allow an attacker to perform unauthorized configuration queries or minor modifications, potentially impacting the integrity and availability of the time service. The issue is addressed in NTP 4.2.8p7.
Affected products
- NTP Project NTP Before 4.2.8p7
Timeline
- 2016-01-27: advisory: Cisco security advisory published
- 2017-01-30: disclosed: NVD publication date
References
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00059.html
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00060.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00020.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00038.html
- http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00048.html
- http://lists.opensuse.org/opensuse-updates/2016-05/msg00114.html
- http://support.ntp.org/bin/view/Main/NtpBug2947