CVE-2015-7974
Summary
| CVE | CVE-2015-7974 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-01-26 19:59:00 UTC |
| Updated | 2021-04-26 17:42:00 UTC |
| Description | NTP 4.x before 4.2.8p6 and 4.3.x before 4.3.90 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via an arbitrary trusted key, aka a "skeleton key." |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| NTP CVE-2015-7974 Symmetric Key Encryption Authentication Security Bypass Vulnerability |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| Document Display | HPE Support Center |
CONFIRM |
h20566.www2.hpe.com |
Third Party Advisory |
| NTP: Multiple vulnerabilities (GLSA 201607-15) — Gentoo Security |
GENTOO |
security.gentoo.org |
Third Party Advisory |
| Siemens TIM 4R-IE Devices | CISA |
MISC |
us-cert.cisa.gov |
|
| Cisco Talos - Talos 2016 0071 |
MISC |
www.talosintel.com |
Exploit, Third Party Advisory |
| ntp Multiple Flaws Let Remote Users Spoof Messages, Obtain Potentially Sensitive Information, and Deny Service - SecurityTracker |
SECTRACK |
www.securitytracker.com |
Third Party Advisory, VDB Entry |
| January 2016 Network Time Protocol Daemon (ntpd) Vulnerabilities in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
Third Party Advisory |
| FreeBSD-SA-16:09 |
FREEBSD |
security.FreeBSD.org |
Third Party Advisory |
| Document Display | HPE Support Center |
CONFIRM |
h20566.www2.hpe.com |
Third Party Advisory |
| support.ntp.org/bin/view/Main/NtpBug2936 |
CONFIRM |
support.ntp.org |
Vendor Advisory |
| Bug 2936 – Skeleton Key: Any system knowing the trusted key can serve time |
CONFIRM |
bugs.ntp.org |
Issue Tracking, Vendor Advisory |
| cert-portal.siemens.com/productcert/pdf/ssa-497656.pdf |
CONFIRM |
cert-portal.siemens.com |
|
| Red Hat Customer Portal |
REDHAT |
rhn.redhat.com |
Third Party Advisory |
| Debian -- Security Information -- DSA-3629-1 ntp |
DEBIAN |
www.debian.org |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 590721 Siemens TIM 4R-IE Devices Multiple Vulnerabilities (ICSA-21-103-11)