CVE-2016-4955

Description

ntpd in NTP 4.x before 4.2.8p8, when autokey is enabled, allows remote attackers to cause a denial of service (peer-variable clearing and association outage) by sending (1) a spoofed crypto-NAK packet or (2) a packet with an incorrect MAC value at a certain time.

Risk Information

Base Score
5.9
MODERATE
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
1.902

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco Application and Content Networking System (ACNS) SoftwareNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco Application Policy Infrastructure Controller (APIC)NCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco Digital Content Manager (DCM) SoftwareNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco Emergency ResponderNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco Jabber GuestNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco MediaSenseNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco Paging ServerNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco Prime InfrastructureNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco Prime Service CatalogNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco Telepresence ConductorNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco TelePresence ISDN LinkNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco UCS DirectorNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco Unified MeetingPlaceNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco Unified SIP ProxyNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco Unity ConnectionNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco Unity ExpressNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco IronPort Encryption Appliance SoftwareNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco Email EncryptionNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco Firepower Management Center Virtual ApplianceNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco 1000 Series Connected Grid RoutersNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco Data Center Network ManagerNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For CiscoPro Workgroup EtherSwitch SoftwareNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco Nexus 1000V Switch for VMware vSphereNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco UCS Central SoftwareNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco Prime Network Analysis Module SoftwareNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco Prime CollaborationNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco Virtual Topology SystemNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco Network Convergence System 540 Series RoutersNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco Network Convergence System 6000 Series RoutersNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco Digital Media ManagerNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco Video Networking SolutionsNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco Unified Communications LicensingNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco Telepresence Integrator C SeriesNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco TelePresence Video Communication Server SoftwareNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco IPICS Server SoftwareNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco Videoscape Distribution Suite for Internet StreamingNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco NAC Appliance (Clean Access)NCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco NAC Appliance 3300 SeriesNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco Wide Area Application Services (WAAS) AppliancesNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco ASA Next-Generation Firewall ServicesNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco Support ToolsNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco Physical Access GatewaysNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco Identity Services EngineNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco IPS 4200 Series SensorsNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco Videoscape Distribution Suite Transparent CachingNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco ASR 1000 Series Aggregation Services RoutersNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco Cloud Services Router 1000V SeriesNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco Catalyst 3850 Series SwitchesNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco Catalyst 3650 Series SwitchesNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco 4000 Series Integrated Services RoutersNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco 1000 Series Integrated Services RoutersNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco Catalyst 9300 Series SwitchesNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco Catalyst 9500 Series SwitchesNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco Catalyst 9400 Series SwitchesNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco 1100 Series Industrial Integrated Services RoutersNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco Catalyst 9200 Series SwitchesNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco Catalyst 9600 Series SwitchesNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco Catalyst 9800 Series Wireless ControllersNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco Hosted Collaboration Solution (HCS)NCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco Virtualization Experience Client 6000 SeriesNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For MPEG-4 EncodersNCM
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016 For Cisco Policy Suite for MobileNCM
CVE-2016-4955NCM
Concurrent Execution using Shared Resource with Improper Synchronization (Race Condition) Vulnerability (CVE-2016-4955)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1705634Security Update for Cisco Application and Content Networking System (ACNS) Software 3.0(0)A5(3.1a)
PATCH-1706006Security Update for Cisco Application Policy Infrastructure Controller (APIC) 1.3(2k)
PATCH-1706007Security Update for Cisco Digital Content Manager (DCM) Software 20.0.0
PATCH-1706049Security Update for Cisco Emergency Responder 12.0(0.98000.50)
PATCH-1705783Security Update for Cisco Jabber Guest 10.6(11)
PATCH-1705879Security Update for Cisco MediaSense 11.5(1.10000.6)
PATCH-1706011Security Update for Cisco Paging Server 12.0(1)
PATCH-1705595Security Update for Cisco Prime Infrastructure 2.2(2)
PATCH-1706010Security Update for Cisco Prime Service Catalog 11.1_VA_OS_Patch
PATCH-1705862Security Update for Cisco TelePresence Conductor XC4.3
PATCH-1705893Security Update for Cisco TelePresence ISDN Link IL1.1.7
PATCH-1705947Security Update for Cisco UCS Director 6.0(1.0)
PATCH-1705973Security Update for Cisco Unified MeetingPlace 8.6(2.45)
PATCH-1705497Security Update for Cisco Unified SIP Proxy 8.5(5)
PATCH-1706048Security Update for Cisco Unity Connection 12.0(0.97000.184)
PATCH-1703070Security Update for Cisco Unity Express 6.2.1
PATCH-1705938Security Update for Cisco Firepower Management Center Virtual Appliance 6.1.0.1
PATCH-1705873Security Update for Cisco 1000 Series Connected Grid Routers 15.6(3.0q)M
PATCH-1706034Security Update for Cisco Data Center Network Manager 10.1(1.158)S0
PATCH-1706035Security Update for CiscoPro Workgroup EtherSwitch Software 6.0(2)A8(4)
PATCH-1705949Security Update for Cisco Nexus 1000V Switch for VMware vSphere 5.2(1)SV3(3.1)
PATCH-1705950Security Update for Cisco UCS Central Software 2.0(1a)
PATCH-1706008Security Update for Cisco Prime Network Analysis Module Software 6.2(3)
PATCH-1705997Security Update for Cisco Prime Collaboration 11.0(0.815)
PATCH-1705711Security Update for Cisco Virtual Topology System 2.2(1)
PATCH-1706041Security Update for Cisco Network Convergence System 540 Series Routers 6.4.1.8i.BASE
PATCH-1705630Security Update for Cisco Network Convergence System 6000 Series Routers 6.1.4
PATCH-1705797Security Update for Cisco Digital Media Manager 5.6.3
PATCH-1705954Security Update for Cisco Video Networking Solutions 2.6.9
PATCH-1706042Security Update for Cisco Unified Communications Licensing 11.5(1.12001.2)
PATCH-1706043Security Update for Cisco Telepresence Integrator C Series 9.1.1
PATCH-1706044Security Update for Cisco TelePresence Video Communication Server Software X8.9.2
PATCH-1705988Security Update for Cisco IPICS Server Software 4.10(2)
PATCH-1705993Security Update for Cisco Videoscape Distribution Suite for Internet Streaming 3.11(6.2)
PATCH-1705725Security Update for Cisco NAC Appliance (Clean Access) 4.9(5)
PATCH-1706001Security Update for Cisco Wide Area Application Services (WAAS) Appliances 6.3(0.185)
PATCH-1705897Security Update for Cisco ASA Next-Generation Firewall Services 100.6(0.0.181)
PATCH-1706002Security Update for Cisco Identity Services Engine 2.0(0.905)
PATCH-1705754Security Update for Cisco IPS 4200 Series Sensors 7.3(5)P1
PATCH-1705898Security Update for Cisco ASR 1000 Series Aggregation Services Routers Denali-16.3.4a
PATCH-1705899Security Update for Cisco Cloud Services Router 1000V Series Denali-16.3.4a
PATCH-1705900Security Update for Cisco Catalyst 3850 Series Switches Denali-16.3.4a
PATCH-1705832Security Update for Cisco Catalyst 3650 Series Switches Everest-16.5.1
PATCH-1705901Security Update for Cisco 4000 Series Integrated Services Routers Denali-16.3.4a
PATCH-1705902Security Update for Cisco 1000 Series Integrated Services Routers Denali-16.3.4a
PATCH-1705903Security Update for Cisco Catalyst 9300 Series Switches Denali-16.3.4a
PATCH-1705904Security Update for Cisco Catalyst 9500 Series Switches Denali-16.3.4a
PATCH-1705905Security Update for Cisco Catalyst 9400 Series Switches Denali-16.3.4a
PATCH-1705906Security Update for Cisco 1100 Series Industrial Integrated Services Routers Denali-16.3.4a
PATCH-1705907Security Update for Cisco Catalyst 9200 Series Switches Denali-16.3.4a
PATCH-1705908Security Update for Cisco Catalyst 9600 Series Switches Denali-16.3.4a
PATCH-1705909Security Update for Cisco Catalyst 9800 Series Wireless Controllers Denali-16.3.4a
PATCH-1706050Security Update for Cisco Hosted Collaboration Solution (HCS) 11.5(1.93540.24)
PATCH-1705446Security Update for Cisco Virtualization Experience Client 6000 Series 9.3(0)
PATCH-1705812Security Update for Cisco Policy Suite for Mobile 8.1.0

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234