MEDIUM · 5.3

CVE-2018-7170

ntpd in ntp 4.2.x before 4.2.8p7 and 4.3.x before 4.3.92 allows authenticated users that know the private symmetric key to create arbitrarily-many ephemeral associations in order to win the clock sele...

Vulnerability Description

ntpd in ntp 4.2.x before 4.2.8p7 and 4.3.x before 4.3.92 allows authenticated users that know the private symmetric key to create arbitrarily-many ephemeral associations in order to win the clock selection of ntpd and modify a victim's clock via a Sybil attack. This issue exists because of an incomplete fix for CVE-2016-1549.

CVSS Score

5.3

MEDIUM

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
NtpNtp>= 4.2.0, < 4.2.8
SynologyRouter Manager>= 1.1, < 1.1.6-6931-3
SynologySkynas< 6.1.5-15254
SynologyVirtual Diskstation Manager< 6.1.6-15266
SynologyDiskstation Manager>= 5.2, < 6.1.6-15266
SynologyVs960Hd Firmware< 2.2.3-1505
SynologyVs960Hd-
NetappHci-
NetappSolidfire-
HpeHpux-Ntp< c.4.2.8.4.0

References

FAQ

What is CVE-2018-7170?

CVE-2018-7170 is a vulnerability with a CVSS score of 5.3 (MEDIUM). ntpd in ntp 4.2.x before 4.2.8p7 and 4.3.x before 4.3.92 allows authenticated users that know the private symmetric key to create arbitrarily-many ephemeral associations in order to win the clock sele...

How severe is CVE-2018-7170?

CVE-2018-7170 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-7170?

Check the references section above for vendor advisories and patch information. Affected products include: Ntp Ntp, Synology Router Manager, Synology Skynas, Synology Virtual Diskstation Manager, Synology Diskstation Manager.