7.5
CVSSv3

CVE-2016-1384

Published: 20/04/2016 Updated: 03/12/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

The NTP implementation in Cisco IOS 15.1 and 15.5 and IOS XE 3.2 up to and including 3.17 allows remote malicious users to modify the system time via crafted packets, aka Bug ID CSCux46898.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ios 15.5\\(1\\)s4

cisco ios 15.5\\(3\\)sn

cisco ios 15.5\\(2\\)s2

cisco ios 15.5\\(2\\)s1

cisco ios 15.5\\(2\\)s

cisco ios 15.5\\(1\\)s

cisco ios 15.1\\(3\\)s1

cisco ios 15.1\\(2\\)s2

cisco ios 15.5\\(3\\)m0a

cisco ios 15.5\\(3\\)m1

cisco ios 15.5\\(1\\)s1

cisco ios 15.5\\(3\\)m

cisco ios 15.1\\(3\\)s2

cisco ios 15.1\\(3\\)s0a

cisco ios 15.1\\(1\\)s

cisco ios 15.1\\(2\\)s

cisco ios 15.5\\(3\\)s1a

cisco ios 15.5\\(3\\)s1

cisco ios 15.5\\(2\\)t

cisco ios 15.5\\(3\\)s

cisco ios 15.1\\(3\\)s5

cisco ios 15.1\\(3\\)s3

cisco ios 15.1\\(3\\)s4

cisco ios 15.1\\(3\\)s

cisco ios 15.1\\(1\\)s1

cisco ios 15.5\\(3\\)s0a

cisco ios 15.5\\(2\\)s3

cisco ios 15.5\\(1\\)s3

cisco ios 15.5\\(1\\)s2

cisco ios 15.1\\(3\\)s5a

cisco ios 15.1\\(3\\)s6

cisco ios 15.1\\(2\\)s1

cisco ios 15.1\\(1\\)s2

cisco ios xe 3.7.1as

cisco ios xe 3.8.0e

cisco ios xe 3.7.2ts

cisco ios xe 3.13.0as

cisco ios xe 3.16.3s

cisco ios xe 3.13.5s

cisco ios xe 3.16.2s

cisco ios xe 3.6.3e

cisco ios xe 3.17.1s

cisco ios xe 3.17.0s

cisco ios xe 3.7.2e

cisco ios xe 3.8.0ex

cisco ios xe 3.8.1e

cisco ios xe 3.4.7sg

cisco ios xe 3.2.0ja

cisco ios xe 3.10.1xbs

cisco ios xe 3.16.2as

cisco ios xe 3.10.7s

cisco ios xe 3.10.2ts

cisco ios xe 3.15.1s

cisco ios xe 3.13.3s

cisco ios xe 3.2.10sg

cisco ios xe 3.10.01s

cisco ios xe 3.3.4se

cisco ios xe 3.3.3se

cisco ios xe 3.3.2se

cisco ios xe 3.14.2s

cisco ios xe 3.11.4s

cisco ios xe 3.12.3s

cisco ios xe 3.13.2s

cisco ios xe 3.4.5sg

cisco ios xe 3.4.4sg

cisco ios xe 3.4.3sg

cisco ios xe 3.11.0s

cisco ios xe 3.9.2s

cisco ios xe 3.12.0s

cisco ios xe 3.11.1s

cisco ios xe 3.3.1sg

cisco ios xe 3.4.2sg

cisco ios xe 3.2.3se

cisco ios xe 3.2.2se

cisco ios xe 3.8.2s

cisco ios xe 3.8.1s

cisco ios xe 3.2.1xo

cisco ios xe 3.2.0xo

cisco ios xe 3.5.1s

cisco ios xe 3.5.0s

cisco ios xe 3.3.2s

cisco ios xe 3.3.1s

cisco ios xe 3.7.1e

cisco ios xe 3.7.0e

cisco ios xe 3.4.1sq

cisco ios xe 3.2.9sg

cisco ios xe 3.2.8sg

cisco ios xe 3.10.6s

cisco ios xe 3.7.7s

cisco ios xe 3.13.1s

cisco ios xe 3.6.1e

cisco ios xe 3.3.2xo

cisco ios xe 3.3.1xo

cisco ios xe 3.7.6s

cisco ios xe 3.7.5s

cisco ios xe 3.10.0as

cisco ios xe 3.10.2s

cisco ios xe 3.4.0sg

cisco ios xe 3.3.2sg

cisco ios xe 3.2.1se

cisco ios xe 3.3.0xo

cisco ios xe 3.8.0s

cisco ios xe 3.7.4s

cisco ios xe 3.7.1s

cisco ios xe 3.7.0s

cisco ios xe 3.4.4s

cisco ios xe 3.4.3s

cisco ios xe 3.2.2s

cisco ios xe 3.2.1s

cisco ios xe 3.4.0s

cisco ios xe 3.9.0as

cisco ios xe 3.9.1as

cisco ios xe 3.5.2sq

cisco ios xe 3.5.1sq

cisco ios xe 3.15.1cs

cisco ios xe 3.13.2as

cisco ios xe 3.12.4s

cisco ios xe 3.12.0as

cisco ios xe 3.6.2e

cisco ios xe 3.16.0s

cisco ios xe 3.4.6sg

cisco ios xe 3.4.0as

cisco ios xe 3.3.0sq

cisco ios xe 3.3.5se

cisco ios xe 3.14.4s

cisco ios xe 3.14.3s

cisco ios xe 3.15.0s

cisco ios xe 3.14.0s

cisco ios xe 3.5.2e

cisco ios xe 3.5.1e

cisco ios xe 3.11.3s

cisco ios xe 3.10.5s

cisco ios xe 3.13.0s

cisco ios xe 3.11.2s

cisco ios xe 3.5.0e

cisco ios xe 3.3.1se

cisco ios xe 3.4.1sg

cisco ios xe 3.2.3sg

cisco ios xe 3.2.2sg

cisco ios xe 3.9.0s

cisco ios xe 3.9.1s

cisco ios xe 3.4.5s

cisco ios xe 3.3.0sg

cisco ios xe 3.6.0s

cisco ios xe 3.5.2s

cisco ios xe 3.2.0sg

cisco ios xe 3.4.1s

cisco ios xe 3.7.0xas

cisco ios xe 3.7.0bs

cisco ios xe 3.7.4as

cisco ios xe 3.7.3e

cisco ios xe 3.6.4e

cisco ios xe 3.16.0cs

cisco ios xe 3.15.3s

cisco ios xe 3.16.1as

cisco ios xe 3.13.4s

cisco ios xe 3.16.1s

cisco ios xe 3.15.2s

cisco ios xe 3.6.2ae

cisco ios xe 3.5.0sq

cisco ios xe 3.4.0sq

cisco ios xe 3.3.1sq

cisco ios xe 3.2.7sg

cisco ios xe 3.2.6sg

cisco ios xe 3.2.3s

cisco ios xe 3.14.1s

cisco ios xe 3.6.0e

cisco ios xe 3.5.3e

cisco ios xe 3.12.2s

cisco ios xe 3.12.1s

cisco ios xe 3.10.4s

cisco ios xe 3.10.3s

cisco ios xe 3.10.1s

cisco ios xe 3.10.0s

cisco ios xe 3.2.5sg

cisco ios xe 3.2.4sg

cisco ios xe 3.3.0se

cisco ios xe 3.2.0se

cisco ios xe 3.7.3s

cisco ios xe 3.7.2s

cisco ios xe 3.4.6s

cisco ios xe 3.6.2s

cisco ios xe 3.6.1s

cisco ios xe 3.4.2s

cisco ios xe 3.2.1sg

cisco ios xe 3.3.0s

cisco ios xe 3.2.0s

Vendor Advisories

A vulnerability in the ntp subsystem of Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to mobilize ntp associations The vulnerability is due to missing authorization checks on certain ntp packets An attacker could exploit this vulnerability by ingressing malicious packets to the ntp daemon An exploit could a ...