CVE-2014-5417: Meinberg Radio Clocks LANTIME M-Series

Published Nov 5, 2014
·
Updated

Cross-site scripting (XSS) vulnerability in Meinberg NTP Server firmware on LANTIME M-Series devices 6.15.019 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Affected Software

16 affected components
Meinberg NTP Server firmware
Meinberg LANTIME M100<=6.15.0.19
Meinberg LANTIME M200<=6.15.0.19
Meinberg LANTIME M300<=6.15.0.19
Meinberg Lantime M3000<=6.15.0.19
Meinberg LANTIME M400<=6.15.0.19
Meinberg LANTIME M600<=6.15.0.19
Meinberg LANTIME M900<=6.15.0.19
All of the following
Meinberg NTP Server firmware
Any of the following
Meinberg LANTIME M100<=6.15.0.19
Meinberg LANTIME M200<=6.15.0.19
Meinberg LANTIME M300<=6.15.0.19
Meinberg Lantime M3000<=6.15.0.19
Meinberg LANTIME M400<=6.15.0.19
Meinberg LANTIME M600<=6.15.0.19
Meinberg LANTIME M900<=6.15.0.19

Remediation

Information

Meinberg’s firmware update, Version 6.15.020, resolves this vulnerability. Please contact Meinberg customer service for information on how to download and install the firmware update, or obtain the update at the following online location: http://news.meinberg.de/259 Meinberg – Radio Clocks Lange Wand 9 D-31812 Bad Pyrmont Phone: ++49(0)5281-9309 0 Fax: ++49(0)5281-9309 30 http:www.meinberg.de http://www.meinberg.de/ Email: info@meinberg.de

Event History

Nov 5, 2014
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
RemedyDescriptionSeverity
Data Sourced
via NVD·11:55 AM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2014-5417?

CVE-2014-5417 is classified as a medium severity cross-site scripting (XSS) vulnerability.

2

How do I fix CVE-2014-5417?

To fix CVE-2014-5417, upgrade the Meinberg NTP Server firmware to a version later than 6.15.019.

3

Which devices are affected by CVE-2014-5417?

CVE-2014-5417 affects Meinberg LANTIME M-Series devices running firmware version 6.15.019 and earlier.

4

What type of vulnerability is CVE-2014-5417?

CVE-2014-5417 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web scripts or HTML.

5

Are there any mitigations for CVE-2014-5417?

The best mitigation for CVE-2014-5417 is to ensure that the firmware is updated to a safe version and to restrict access to the management interface.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203