CVE-2016-4953: High severity siemens tim 4r-ie vulnerability
Published Jul 5, 2016
·Updated
ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (ephemeral-association demobilization) by sending a spoofed crypto-NAK packet with incorrect authentication data at a certain time.
Affected Software
44 affected components
Siemens TIM 4R-IE (incl. SIPLUS NET variants)
Siemens TIM 4R-IE DNP3 (incl. SIPLUS NET variants)
Siemens SIMATIC NET CP 443-1 OPC UA
NTP ntp>=4.2.0<4.2.8
NTP ntp>=4.3.0<4.3.93
NTP ntp=4.2.8
NTP ntp=4.2.8-p1
NTP ntp=4.2.8-p1-beta1
NTP ntp=4.2.8-p1-beta2
NTP ntp=4.2.8-p1-beta3
NTP ntp=4.2.8-p1-beta4
NTP ntp=4.2.8-p1-beta5
NTP ntp=4.2.8-p1-rc1
NTP ntp=4.2.8-p1-rc2
NTP ntp=4.2.8-p2
NTP ntp=4.2.8-p2-rc1
NTP ntp=4.2.8-p2-rc2
NTP ntp=4.2.8-p2-rc3
NTP ntp=4.2.8-p3
NTP ntp=4.2.8-p3-rc1
NTP ntp=4.2.8-p3-rc2
NTP ntp=4.2.8-p3-rc3
NTP ntp=4.2.8-p4
NTP ntp=4.2.8-p5
NTP ntp=4.2.8-p6
NTP ntp=4.2.8-p7
Oracle Solaris=10
Oracle Solaris=11.3
SUSE Manager=2.1
SUSE Manager Proxy=2.1
SUSE Openstack Cloud=5
openSUSE Leap=42.1
openSUSE openSUSE=13.2
SUSE Linux Enterprise Desktop=12-sp1
SUSE Linux Enterprise Server=11-sp2
SUSE Linux Enterprise Server=11-sp3
SUSE Linux Enterprise Server=11-sp4
SUSE Linux Enterprise Server=12-sp1
Siemens Simatic Net Cp 443-1 Opc Ua Firmware
Siemens SIMATIC NET CP 443-1 OPC UA
Siemens Tim 4r-ie Firmware
Siemens Tim 4r-ie
Siemens Tim 4r-ie Dnp3 Firmware
Siemens Tim 4r-ie Dnp3
Remediation
Patch Available
Event History
Jul 5, 2016
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
1
What is the severity of CVE-2016-4953?
CVE-2016-4953 is classified as a medium severity vulnerability due to its potential to cause denial of service.
2
How do I fix CVE-2016-4953?
To fix CVE-2016-4953, you should update NTP to version 4.2.8p8 or later.
3
What types of attacks are possible with CVE-2016-4953?
CVE-2016-4953 allows remote attackers to send spoofed crypto-NAK packets leading to denial of service.
4
Which NTP versions are affected by CVE-2016-4953?
NTP versions before 4.2.8p8 and 4.3.93 are affected by CVE-2016-4953.
5
What devices are impacted by CVE-2016-4953?
Devices including Siemens TIM 4R-IE and SIMATIC NET CP 443-1 OPC UA can be impacted by CVE-2016-4953.