Denial of service in ntp - CVE-2013-5211
Published: July 1, 2016 / Updated: March 19, 2020
Vulnerability identifier: #VU4013
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-5211
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS conditions on the target system.
The weakness exists due to an error in the monlist feature in ntp_request.c. By sending a specially crafted REQ_MON_GETLIST or REQ_MON_GETLIST_1 request, a remote attacker can consume available CPU resources and cause the server to crash.
Successful exploitation of the vulnerability results in denial of service on the vulnerable system.
Note: the vulnerability was being actively exploited.
The weakness exists due to an error in the monlist feature in ntp_request.c. By sending a specially crafted REQ_MON_GETLIST or REQ_MON_GETLIST_1 request, a remote attacker can consume available CPU resources and cause the server to crash.
Successful exploitation of the vulnerability results in denial of service on the vulnerable system.
Note: the vulnerability was being actively exploited.
Affected software
ntp
IBM BladeCenter Advanced Management Module
Gentoo Linux
Junos OS
Slackware Linux
Opensuse
Junos OS Evolved
HP-UX
IBM BladeCenter Advanced Management Module
Gentoo Linux
Junos OS
Slackware Linux
Opensuse
Junos OS Evolved
HP-UX
How to mitigate CVE-2013-5211
Update to version 4.2.7p26.
Junos OS - addressed in versions 11.4R12, 12.1X44-D35, 12.1X45-D25, 12.1X46-D15, 12.1X47-D10, 12.1R10, 12.2R8, 12.3X48-D95, 12.3R7, 12.3R12-S15, 13.1R4-S2, 13.2R4, 13.3R2, 14.1X53-D53, 14.1R1, 15.1x49-D190, 15.1R7-S6, 16.1R7-S6, 16.2R3, 17.1R2-S11, 17.1R3-S1, 17.2R1-S9, 17.2R2-S8, 17.2R3-S3, 17.3R2-S5, 17.3R3-S6, 17.4R2-S7, 17.4R3, 18.1R3-S8, 18.2R2-S7, 18.2R3-S1, 18.3R1-S5, 18.3R2-S2, 18.3R3, 18.4R1-S4, 18.4R2-S1, 18.4R3, 19.1R1-S3, 19.1R2, 19.2R1-S1, 19.2R2, 19.3R1
Junos OS Evolved - addressed in versions 20.1R1-EVO, 20.4R2-EVO, 20.4R3-S7-EVO, 20.4R3-S8-EVO, 21.1R2-EVO, 21.2R3-S5-EVO, 21.2R3-S6-EVO, 21.3R2-EVO, 21.3R3-S4-EVO, 21.3R3-S5-EVO, 21.4R1-EVO, 21.4R3-S4-EVO, 22.1R3-S3-EVO, 22.1R3-EVO, 22.2R3-S2-EVO, 22.2R3-EVO, 22.3R2-S2-EVO, 22.3R2-EVO, 22.3R3-S1-EVO, 22.4R1-EVO, 22.4R2-S1-EVO, 22.4R2-EVO, 22.4R3-EVO, 23.1R1-EVO, 23.2R1-EVO
IBM BladeCenter Advanced Management Module - update to 3.66D
Junos OS Evolved - addressed in versions 20.1R1-EVO, 20.4R2-EVO, 20.4R3-S7-EVO, 20.4R3-S8-EVO, 21.1R2-EVO, 21.2R3-S5-EVO, 21.2R3-S6-EVO, 21.3R2-EVO, 21.3R3-S4-EVO, 21.3R3-S5-EVO, 21.4R1-EVO, 21.4R3-S4-EVO, 22.1R3-S3-EVO, 22.1R3-EVO, 22.2R3-S2-EVO, 22.2R3-EVO, 22.3R2-S2-EVO, 22.3R2-EVO, 22.3R3-S1-EVO, 22.4R1-EVO, 22.4R2-S1-EVO, 22.4R2-EVO, 22.4R3-EVO, 23.1R1-EVO, 23.2R1-EVO
IBM BladeCenter Advanced Management Module - update to 3.66D
Links to Public Exploits and PoC-codes
- Exploit #20 - SSDP ssdp:all M-SEARCH Amplification Scanner (March 18, 2020)
- Exploit #21 - UDP Amplification Scanner (March 18, 2020)
- Exploit #22 - Portmapper Amplification Scanner (March 18, 2020)
- Exploit #23 - NTP Mode 6 UNSETTRAP DRDoS Scanner (March 18, 2020)
- Exploit #24 - NTP Mode 7 GET_RESTRICT DRDoS Scanner (March 18, 2020)
- Exploit #25 - NTP Mode 6 REQ_NONCE DRDoS Scanner (March 18, 2020)
- Exploit #26 - NTP Clock Variables Disclosure (March 18, 2020)
- Exploit #27 - NTP Mode 7 PEER_LIST_SUM DoS Scanner (March 18, 2020)
- Exploit #28 - NTP Mode 7 PEER_LIST DoS Scanner (March 18, 2020)
- Exploit #29 - NTP Monitor List Scanner (March 18, 2020)
- Exploit #733 - NTP ntpd monlist Query Reflection - Denial of Service (March 18, 2020)
External References
Related Security Bulletins
- Denial of service in ntp.org ntp
- Gentoo update for NTP
- Slackware Linux update for ntp
- openSUSE update for ntp
- Denial of service in HP-UX Running NTP
- Multiple NTP vulnerabilities in Junos OS and Junos OS Evolved
- Denial of service in Junos OS NTP server
- Multiple vulnerabilities in IBM BladeCenter Advanced Management Module