First published: Tue Jul 05 2016(Updated: )
ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (ephemeral-association demobilization) by sending a spoofed crypto-NAK packet with incorrect authentication data at a certain time.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens TIM 4R-IE | ||
Siemens TIM 4R-IE DNP3 | ||
Siemens Simatic Net CP 443-1 OPC UA Firmware | ||
NTP | >=4.2.0<4.2.8 | |
NTP | >=4.3.0<4.3.93 | |
NTP | =4.2.8 | |
NTP | =4.2.8-p1 | |
NTP | =4.2.8-p1-beta1 | |
NTP | =4.2.8-p1-beta2 | |
NTP | =4.2.8-p1-beta3 | |
NTP | =4.2.8-p1-beta4 | |
NTP | =4.2.8-p1-beta5 | |
NTP | =4.2.8-p1-rc1 | |
NTP | =4.2.8-p1-rc2 | |
NTP | =4.2.8-p2 | |
NTP | =4.2.8-p2-rc1 | |
NTP | =4.2.8-p2-rc2 | |
NTP | =4.2.8-p2-rc3 | |
NTP | =4.2.8-p3 | |
NTP | =4.2.8-p3-rc1 | |
NTP | =4.2.8-p3-rc2 | |
NTP | =4.2.8-p3-rc3 | |
NTP | =4.2.8-p4 | |
NTP | =4.2.8-p5 | |
NTP | =4.2.8-p6 | |
NTP | =4.2.8-p7 | |
Oracle Solaris and Zettabyte File System (ZFS) | =10 | |
Oracle Solaris and Zettabyte File System (ZFS) | =11.3 | |
SUSE Manager Server | =2.1 | |
SUSE Manager Proxy | =2.1 | |
openSUSE OpenStack Cloud | =5 | |
SUSE Linux | =42.1 | |
openSUSE | =13.2 | |
SUSE Linux Enterprise Desktop | =12-sp1 | |
SUSE Linux Enterprise Server | =11-sp2 | |
SUSE Linux Enterprise Server | =11-sp3 | |
SUSE Linux Enterprise Server | =11-sp4 | |
SUSE Linux Enterprise Server | =12-sp1 | |
siemens SIMATIC cp443-1 OPC UA firmware | ||
Siemens Simatic Net CP 443-1 OPC UA Firmware | ||
Siemens TIM 4R-IE DNP3 | ||
siemens SIMATIC TIM 4R-IE | ||
Siemens TIM 4R-IE | ||
Siemens TIM 4R-IE |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4953 is classified as a medium severity vulnerability due to its potential to cause denial of service.
To fix CVE-2016-4953, you should update NTP to version 4.2.8p8 or later.
CVE-2016-4953 allows remote attackers to send spoofed crypto-NAK packets leading to denial of service.
NTP versions before 4.2.8p8 and 4.3.93 are affected by CVE-2016-4953.
Devices including Siemens TIM 4R-IE and SIMATIC NET CP 443-1 OPC UA can be impacted by CVE-2016-4953.