Multiples vulnerabilities in NTP

Advisory ID CVE Number Date discovered Severity Advisory revision
STORM-2016-004 CVE-2015-8158 , CVE-2015-8138 , CVE-2015-7979 , CVE-2015-7978 , CVE-2015-7977 , CVE-2015-7976 , CVE-2015-7975 , CVE-2015-7974 , CVE-2015-7973 01/27/2016 low v1

Vulnerability details

NTP 2.4.8p8 fixes multiples vulnerabilities in ntp client and ntp server.

Impacted products

ProductsSeverityDetail
Stormshield Network Security low SNS uses a vulnerable version of NTP
Netasq low Netasq uses a vulnerable version of NTP

Revisions

Version Date Description
v1 Initial release


Stormshield Network Security

CVSS v2 Overall Score: 3.2      

Analysis

Impacted version

SNS uses a vulnerable version of NTP. An attacker can crash the ntp daemon or client.

  • SNS 1.0.0 to 2.4.2

Workaround solution

Solution

Restrict the use of NTP.

The 2.5.0 update will fix this vulnerability.



Access vector Access complexity Authentication Confidentiality impact Integrity impact Availability impact
Network Medium None None Partial Partial
CVSS Base score: 5.8 CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:P)
Exploitability Remediation Level Report Confidence
Unproven that exploit exists Official fix Confirmed
CVSS Temporal score: 4.3 CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:P/E:U/RL:OF/RC:C)
Collateral Damage Potential Target Distribution
None Medium [26-75%]
CVSS Environmental score: 3.2 CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:P/E:U/RL:OF/RC:C/CDP:N/TD:M/CR:ND/IR:ND/AR:ND)


Netasq

CVSS v2 Overall Score: 3.2      

Analysis

Impacted version

Netasq uses a vulnerable version of NTP. An attacker can crash the ntp daemon or client.

  • Netasq 9.1.0 to 9.1.8

Workaround solution

Solution

Restrict the use of NTP.

The 9.1.9 update will fix this vulnerability.



Access vector Access complexity Authentication Confidentiality impact Integrity impact Availability impact
Network Medium None None Partial Partial
CVSS Base score: 5.8 CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:P)
Exploitability Remediation Level Report Confidence
Unproven that exploit exists Official fix Confirmed
CVSS Temporal score: 4.3 CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:P/E:U/RL:OF/RC:C)
Collateral Damage Potential Target Distribution
None Medium [26-75%]
CVSS Environmental score: 3.2 CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:P/E:U/RL:OF/RC:C/CDP:N/TD:M/CR:ND/IR:ND/AR:ND)