QID 330150

Date Published: 2023-10-16

QID 330150: IBM AIX Denial of Service (DoS) Vulnerability due to NTP (ntp_advisory14)

AIX is vulnerable to a denial of service due to NTP (CVE-2023-26551, CVE-2023-26552, CVE-2023-26553, CVE-2023-26554)

Affected Platform:
AIX 7.2, 7.3

QID Detection Logic (Authenticated):
The detection checks for installed packages version via command : lslpp -L | grep -i ntp.rte It also checks for interim fixes installed using the command emgr -c or instfix -k The detection posts vulnerable if installed package version is less than patched version and interim fixes are also not installed.

Note: The detection requires root privileges to run "emgr -c" to check for patches. In absence of such privileges, the detection may not output actual results.

Successful exploit could allow a remote attacker to cause a denial of service

  • CVSS V3 rated as Medium - 5.6 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    The vendor has released fixes at ntp_advisory14 this vulnerability.

    CVEs related to QID 330150

    Software Advisories
    Advisory ID Software Component Link
    ntp_advisory14 URL Logo aix.software.ibm.com/aix/efixes/security/ntp_advisory14.asc