Authentication Bypass by Spoofing in ntp - CVE-2020-11868

 

Authentication Bypass by Spoofing in ntp - CVE-2020-11868

Published: April 28, 2020 / Updated: October 29, 2023


Vulnerability identifier: #VU27395
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-11868
CWE-ID: CWE-290
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication and perform a denial of service (DoS) attack.

The vulnerability exists due to ntpd allows an off-path attacker to block unauthenticated synchronization via a server mode packet with a spoofed source IP address, because transmissions are rescheduled even when a packet lacks a valid origin timestamp.A remote attacker can bypass authentication and block synchronization.


Affected software

ntp
Gentoo Linux
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Server
Opensuse
Junos OS Evolved
Traffix SDC
BIG-IQ Centralized Management
BIG-IP GTM
BIG-IP FPS
BIG-IP ASM
BIG-IP APM
BIG-IP Analytics
BIG-IP AFM
BIG-IP LTM
BIG-IP PEM
BIG-IP DNS
BIG-IP AAM
BIG-IP Link Controller
BIG-IP
Flex System Chassis Management Module (CMM)
ntp (Red Hat package)
Data Computing Appliance (DCA)

How to mitigate CVE-2020-11868

Install updates from vendor's website.

ntp - update to 4.2.8p14
Junos OS Evolved - addressed in versions 21.2R3-S5-EVO, 21.3R3-S4-EVO, 21.4R3-S4-EVO, 22.1R3-S3-EVO, 22.2R3-EVO, 22.3R2-EVO, 22.4R2-EVO, 23.1R1-EVO
Flex System Chassis Management Module (CMM) - update to 2pet22a-2.5.20a
ntp (Red Hat package) - update to 4.2.6p5-29.el7_8.2
Data Computing Appliance (DCA) - update to 4.3.0.0

External References

Related Security Bulletins