CVE-2015-7871: Critical severity siemens tim 4r-ie vulnerability

Published Oct 22, 2015
·
Updated

Crypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to bypass authentication.

Other sources

The following flaw was found in ntpd:

An error handling logic error exists within ntpd that manifests due to improper error condition handling associated with certain crypto-NAK packets. An unauthenticated, off­-path attacker can force ntpd processes on targeted servers to peer with time sources of the attacker's choosing by transmitting symmetric active crypto­-NAK packets to ntpd. This attack bypasses the authentication typically required to establish a peer association and allows an attacker to make arbitrary changes to system time.

External References:

http://talosintel.com/reports/TALOS-2015-0069/ http://support.ntp.org/bin/view/Main/SecurityNotice#October2015NTPSecurityVulner

Red Hat

Affected Software

94 affected componentsFixes available
redhat/ntp<4.2.8
4.2.8
Siemens TIM 4R-IE (incl. SIPLUS NET variants)
Siemens TIM 4R-IE DNP3 (incl. SIPLUS NET variants)
NTP ntp>=4.2.6<4.2.8
NTP ntp>=4.3.0<4.3.77
NTP ntp=4.2.5-p186
NTP ntp=4.2.5-p187
NTP ntp=4.2.5-p188
NTP ntp=4.2.5-p189
NTP ntp=4.2.5-p190
NTP ntp=4.2.5-p191
NTP ntp=4.2.5-p192
NTP ntp=4.2.5-p193
NTP ntp=4.2.5-p194
NTP ntp=4.2.5-p195
NTP ntp=4.2.5-p196
NTP ntp=4.2.5-p197
NTP ntp=4.2.5-p198
NTP ntp=4.2.5-p199
NTP ntp=4.2.5-p200
NTP ntp=4.2.5-p201
NTP ntp=4.2.5-p202
NTP ntp=4.2.5-p203
NTP ntp=4.2.5-p204
NTP ntp=4.2.5-p205
NTP ntp=4.2.5-p206
NTP ntp=4.2.5-p207
NTP ntp=4.2.5-p208
NTP ntp=4.2.5-p209
NTP ntp=4.2.5-p210
NTP ntp=4.2.5-p211
NTP ntp=4.2.5-p212
NTP ntp=4.2.5-p213
NTP ntp=4.2.5-p214
NTP ntp=4.2.5-p215
NTP ntp=4.2.5-p216
NTP ntp=4.2.5-p217
NTP ntp=4.2.5-p218
NTP ntp=4.2.5-p219
NTP ntp=4.2.5-p220
NTP ntp=4.2.5-p221
NTP ntp=4.2.5-p222
NTP ntp=4.2.5-p223
NTP ntp=4.2.5-p224
NTP ntp=4.2.5-p225
NTP ntp=4.2.5-p226
NTP ntp=4.2.5-p227
NTP ntp=4.2.5-p228
NTP ntp=4.2.5-p229
NTP ntp=4.2.5-p230
NTP ntp=4.2.5-p231_rc1
NTP ntp=4.2.5-p232_rc1
NTP ntp=4.2.5-p233_rc1
NTP ntp=4.2.5-p234_rc1
NTP ntp=4.2.5-p235_rc1
NTP ntp=4.2.5-p236_rc1
NTP ntp=4.2.5-p237_rc1
NTP ntp=4.2.5-p238_rc1
NTP ntp=4.2.5-p239_rc1
NTP ntp=4.2.5-p240_rc1
NTP ntp=4.2.5-p241_rc1
NTP ntp=4.2.5-p242_rc1
NTP ntp=4.2.5-p243_rc1
NTP ntp=4.2.5-p244_rc1
NTP ntp=4.2.5-p245_rc1
NTP ntp=4.2.5-p246_rc1
NTP ntp=4.2.5-p247_rc1
NTP ntp=4.2.5-p248_rc1
NTP ntp=4.2.5-p249_rc1
NTP ntp=4.2.5-p250_rc1
NTP ntp=4.2.8-p1
NTP ntp=4.2.8-p1-beta1
NTP ntp=4.2.8-p1-beta2
NTP ntp=4.2.8-p1-beta3
NTP ntp=4.2.8-p1-beta4
NTP ntp=4.2.8-p1-beta5
NTP ntp=4.2.8-p1-rc1
NTP ntp=4.2.8-p1-rc2
NTP ntp=4.2.8-p2
NTP ntp=4.2.8-p2-rc1
NTP ntp=4.2.8-p2-rc2
NTP ntp=4.2.8-p2-rc3
NTP ntp=4.2.8-p3
NTP ntp=4.2.8-p3-rc1
NTP ntp=4.2.8-p3-rc2
NTP ntp=4.2.8-p3-rc3
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
NetApp OnCommand Balance
NetApp Oncommand Performance Manager
NetApp Oncommand Unified Manager Clustered Data Ontap
NetApp Clustered Data ONTAP
NetApp Data Ontap 7-mode

Event History

Aug 7, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2015-7871?

CVE-2015-7871 has been classified as a medium severity vulnerability due to its potential to allow remote attackers to bypass authentication.

2

How do I fix CVE-2015-7871?

To fix CVE-2015-7871, you should upgrade to NTP version 4.2.8p4 or higher, or 4.3.77 or higher.

3

What systems are affected by CVE-2015-7871?

CVE-2015-7871 affects NTP versions 4.2.x prior to 4.2.8p4 and 4.3.x prior to 4.3.77, as well as various products from Siemens and NetApp that utilize these versions.

4

Is there a workaround for CVE-2015-7871?

There is no specific workaround for CVE-2015-7871; the best course of action is to apply the available updates.

5

What type of vulnerability is CVE-2015-7871?

CVE-2015-7871 is a cryptographic vulnerability that allows attackers to bypass authentication through the exploitation of faulty error handling in NTP.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203