CVE-2016-3989

UnknownEPSS 5.09%

Last modified

CVE-2016-3989 is a vulnerability of currently unknown severity. The NTP time-server interface on Meinberg IMS-LANTIME M3000, IMS-LANTIME M1000, IMS-LANTIME M500, LANTIME M900, LANTIME M600, LANTIME M400, LANTIME M300, LANTIME M200, LANTIME M100, SyncFire 1100, and LCES devices with firmware before 6.20.004 allows remote authenticated users to obtain root privileges for writing to unspecified scripts, and consequently obtain sensitive information or modify data, by leveraging access to the nobody account.. EPSS estimates a 5.09% chance of exploitation in the next 30 days.

Description

The NTP time-server interface on Meinberg IMS-LANTIME M3000, IMS-LANTIME M1000, IMS-LANTIME M500, LANTIME M900, LANTIME M600, LANTIME M400, LANTIME M300, LANTIME M200, LANTIME M100, SyncFire 1100, and LCES devices with firmware before 6.20.004 allows remote authenticated users to obtain root privileges for writing to unspecified scripts, and consequently obtain sensitive information or modify data, by leveraging access to the nobody account.

Metrics

EPSS Probability
5.09%

91.2th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
MeinbergNtp Server Firmware<= 6.0
MeinbergIms-Lantime M1000All versions
MeinbergIms-Lantime M3000All versions
MeinbergIms-Lantime M500All versions
MeinbergLantime M100All versions
MeinbergLantime M200All versions
MeinbergLantime M300All versions
MeinbergLantime M400All versions
MeinbergLantime M600All versions
MeinbergLantime M900All versions
MeinbergLcesAll versions
MeinbergSyncfire 1100All versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2016-3989?
The NTP time-server interface on Meinberg IMS-LANTIME M3000, IMS-LANTIME M1000, IMS-LANTIME M500, LANTIME M900, LANTIME M600, LANTIME M400, LANTIME M300, LANTIME M200, LANTIME M100, SyncFire 1100, and LCES devices with firmware before 6.20.004 allows remote authenticated users to obtain root privileges for writing to unspecified scripts, and consequently obtain sensitive information or modify data, by leveraging access to the nobody account.
How severe is CVE-2016-3989?
Severity scoring for CVE-2016-3989 is pending analysis. The EPSS model estimates a 5.09% probability of exploitation in the next 30 days.
How do I fix CVE-2016-3989?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2016-3989?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST