Information disclosure in Network Time Protocol - CVE-2018-7182
Published: March 1, 2018 / Updated: June 17, 2021
Vulnerability identifier: #VU10798
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-7182
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote unautheticated attacker to obtain potentially sensitive information.
The weakness exists due to insufficient validation user-supplied input. A remote attacker can submit a specially crafted mode 6 packet and gain access to potentially sensitive information.
Affected software
Network Time Protocol
Arch Linux
Amazon Linux AMI
Gentoo Linux
IBM AIX
FreeBSD
Slackware Linux
Ubuntu
Fedora
Flex System Integrated Management Module (IMM2)
System x Integrated Management Module (IMM2)
Flex System Chassis Management Module (CMM)
QLogic 8Gb Intelligent Pass-thru Module & SAN Switch Module for BladeCenter
Flex System FC3171 8Gb SAN Pass-thru
Flex System FC3171 8Gb SAN Switch
Integrated Management Module II (IMM2) for BladeCenter Systems
sntp (Ubuntu package)
ntpdate (Ubuntu package)
ntp (Ubuntu package)
ntp
Arch Linux
Amazon Linux AMI
Gentoo Linux
IBM AIX
FreeBSD
Slackware Linux
Ubuntu
Fedora
Flex System Integrated Management Module (IMM2)
System x Integrated Management Module (IMM2)
Flex System Chassis Management Module (CMM)
QLogic 8Gb Intelligent Pass-thru Module & SAN Switch Module for BladeCenter
Flex System FC3171 8Gb SAN Pass-thru
Flex System FC3171 8Gb SAN Switch
Integrated Management Module II (IMM2) for BladeCenter Systems
sntp (Ubuntu package)
ntpdate (Ubuntu package)
ntp (Ubuntu package)
ntp
How to mitigate CVE-2018-7182
Update to version ntp-4.2.8p11.
Flex System Integrated Management Module (IMM2) - update to 1AOO84C-6.80
System x Integrated Management Module (IMM2) - update to 1AOO84C-6.80
Integrated Management Module II (IMM2) for BladeCenter Systems - update to 1AOO84C-6.80-bc
Flex System Chassis Management Module (CMM) - update to 2pet16c-2.5.12c
sntp (Ubuntu package) - addressed in versions 1:4.2.8p10+dfsg-5ubuntu7.3, 1:4.2.8p12+dfsg-3ubuntu4.20.04.1, 1:4.2.8p12+dfsg-3ubuntu4.20.10.1
ntpdate (Ubuntu package) - addressed in versions 1:4.2.8p10+dfsg-5ubuntu7.3, 1:4.2.8p12+dfsg-3ubuntu4.20.04.1, 1:4.2.8p12+dfsg-3ubuntu4.20.10.1
ntp (Ubuntu package) - addressed in versions 1:4.2.8p10+dfsg-5ubuntu7.3, 1:4.2.8p12+dfsg-3ubuntu4.20.04.1, 1:4.2.8p12+dfsg-3ubuntu4.20.10.1
ntp - addressed in versions 4.2.8p11-1.fc26, 4.2.8p11-1.fc27
QLogic 8Gb Intelligent Pass-thru Module & SAN Switch Module for BladeCenter - update to 7.10.1.45.00
Flex System FC3171 8Gb SAN Pass-thru - update to 9.1.14.02.00
Flex System FC3171 8Gb SAN Switch - update to 9.1.14.02.00
System x Integrated Management Module (IMM2) - update to 1AOO84C-6.80
Integrated Management Module II (IMM2) for BladeCenter Systems - update to 1AOO84C-6.80-bc
Flex System Chassis Management Module (CMM) - update to 2pet16c-2.5.12c
sntp (Ubuntu package) - addressed in versions 1:4.2.8p10+dfsg-5ubuntu7.3, 1:4.2.8p12+dfsg-3ubuntu4.20.04.1, 1:4.2.8p12+dfsg-3ubuntu4.20.10.1
ntpdate (Ubuntu package) - addressed in versions 1:4.2.8p10+dfsg-5ubuntu7.3, 1:4.2.8p12+dfsg-3ubuntu4.20.04.1, 1:4.2.8p12+dfsg-3ubuntu4.20.10.1
ntp (Ubuntu package) - addressed in versions 1:4.2.8p10+dfsg-5ubuntu7.3, 1:4.2.8p12+dfsg-3ubuntu4.20.04.1, 1:4.2.8p12+dfsg-3ubuntu4.20.10.1
ntp - addressed in versions 4.2.8p11-1.fc26, 4.2.8p11-1.fc27
QLogic 8Gb Intelligent Pass-thru Module & SAN Switch Module for BladeCenter - update to 7.10.1.45.00
Flex System FC3171 8Gb SAN Pass-thru - update to 9.1.14.02.00
Flex System FC3171 8Gb SAN Switch - update to 9.1.14.02.00
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Multiple vulnerabilities in Network Time Protocol
- Slackware Linux update for ntp
- FreeBSD update for ntpd
- Arch Linux update for ntp
- Amazon Linux AMI update for ntp
- Gentoo update for NTP
- Multiple vulnerabilities in IBM AIX
- Ubuntu update for ntp
- Multiple vulnerabilities in QLogic 8Gb Intelligent Pass-thru Module and SAN Switch Module for IBM BladeCenter and IBM Flex System FC3171 8Gb SAN Switch & SAN Pass-thru
- Multiple vulnerabilities in IBM Flex System Chassis Management Module (CMM)
- Multiple vulnerabilities in IBM Integrated Management Module II (IMM2) for System x, Flex and BladeCenter Systems
- Ubuntu update for ntp
- Fedora 27 update for ntp
- Fedora 26 update for ntp