CVE-2018-7170
Last modified
CVE-2018-7170 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. ntpd in ntp 4.2.x before 4.2.8p7 and 4.3.x before 4.3.92 allows authenticated users that know the private symmetric key to create arbitrarily-many ephemeral associations in order to win the clock selection of ntpd and modify a victim's clock via a Sybil attack. This issue exists because of an incomplete fix for CVE-2016-1549.. EPSS estimates a 2.76% chance of exploitation in the next 30 days.
Description
ntpd in ntp 4.2.x before 4.2.8p7 and 4.3.x before 4.3.92 allows authenticated users that know the private symmetric key to create arbitrarily-many ephemeral associations in order to win the clock selection of ntpd and modify a victim's clock via a Sybil attack. This issue exists because of an incomplete fix for CVE-2016-1549.
Metrics
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ntp | Ntp | >= 4.2.0, < 4.2.8 |
| Ntp | Ntp | >= 4.3.0, < 4.3.92 |
| Ntp | Ntp | 4.2.8 |
| Synology | Router Manager | >= 1.1, < 1.1.6-6931-3 |
| Synology | Skynas | < 6.1.5-15254 |
| Synology | Virtual Diskstation Manager | < 6.1.6-15266 |
| Synology | Diskstation Manager | >= 5.2, < 6.1.6-15266 |
| Synology | Vs960hd Firmware | < 2.2.3-1505 |
| Netapp | Hci | All versions |
| Netapp | Solidfire | All versions |
| Hpe | Hpux-Ntp | < c.4.2.8.4.0 |
References
- http://packetstormsecurity.com/files/146631/Slackware-Security-Advisory-ntp-Updates.htmlThird Party Advisory, VDB Entry
- http://support.ntp.org/bin/view/Main/NtpBug3415Third Party Advisory
- http://www.securityfocus.com/archive/1/541824/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/103194Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1550214Issue Tracking, Third Party Advisory
- https://security.FreeBSD.org/advisories/FreeBSD-SA-18:02.ntp.ascThird Party Advisory
- https://security.gentoo.org/glsa/201805-12Third Party Advisory
- https://security.netapp.com/advisory/ntap-20180626-0001/Third Party Advisory
- https://www.synology.com/support/security/Synology_SA_18_13Third Party Advisory
- http://packetstormsecurity.com/files/146631/Slackware-Security-Advisory-ntp-Updates.htmlThird Party Advisory, VDB Entry
- http://support.ntp.org/bin/view/Main/NtpBug3415Third Party Advisory
- http://www.securityfocus.com/archive/1/541824/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/103194Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1550214Issue Tracking, Third Party Advisory
- https://security.FreeBSD.org/advisories/FreeBSD-SA-18:02.ntp.ascThird Party Advisory
- https://security.gentoo.org/glsa/201805-12Third Party Advisory
- https://security.netapp.com/advisory/ntap-20180626-0001/Third Party Advisory
- https://www.synology.com/support/security/Synology_SA_18_13Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-7170?
How severe is CVE-2018-7170?
How do I fix CVE-2018-7170?
Are you affected by CVE-2018-7170?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
