CVE-2016-1548
Last modified
CVE-2016-1548 is a vulnerability of currently unknown severity. An attacker can spoof a packet from a legitimate ntpd server with an origin timestamp that matches the peer->dst timestamp recorded for that server. After making this switch, the client in NTP 4.2.8p4 and earlier and NTPSec aa48d001683e5b791a743ec9c575aaf7d867a2b0c will reject all future legitimate server responses. EPSS estimates a 3.84% chance of exploitation in the next 30 days.
Description
An attacker can spoof a packet from a legitimate ntpd server with an origin timestamp that matches the peer->dst timestamp recorded for that server. After making this switch, the client in NTP 4.2.8p4 and earlier and NTPSec aa48d001683e5b791a743ec9c575aaf7d867a2b0c will reject all future legitimate server responses. It is possible to force the victim client to move time after the mode has been changed. ntpq gives no indication that the mode has been switched.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Ntp | Ntp | 4.2.8 | P4 |
References
- http://www.talosintelligence.com/reports/TALOS-2016-0082/Exploit, Third Party Advisory
- http://www.talosintelligence.com/reports/TALOS-2016-0082/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-1548?
How severe is CVE-2016-1548?
How do I fix CVE-2016-1548?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-1541Heap-based buffer overflow in the zip_read_mac_metadata func…
- CVE-2016-1542The RPC API in RSCD agent in BMC BladeLogic Server Automatio…
- CVE-2016-1543The RPC API in the RSCD agent in BMC BladeLogic Server Autom…
- CVE-2016-1544nghttp2 before 1.7.1 allows remote attackers to cause a deni…3.3
- CVE-2016-1546The Apache HTTP Server 2.4.17 and 2.4.18, when mod_http2 is …
- CVE-2016-1547An off-path attacker can cause a preemptible client associat…
- CVE-2016-1549A malicious authenticated peer can create arbitrarily-many e…
- CVE-2016-1550An exploitable vulnerability exists in the message authentic…
- CVE-2016-1551ntpd in NTP 4.2.8p3 and NTPsec a5fb34b9cc89b92a8fef2f4590048…
- CVE-2016-1555(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.…9.8
- CVE-2016-1556Information disclosure in Netgear WN604 before 3.3.3; WNAP21…
- CVE-2016-1557Netgear WNAP320, WNDAP350, and WNDAP360 before 3.5.5.0 revea…
Are you affected by CVE-2016-1548?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
