Beveiligingsadvies

CVE-2015-7974

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2016-01-26 19:00:00
Laatst bijgewerkt 2024-08-06 08:06:31
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

NTP 4.x before 4.2.8p6 and 4.3.x before 4.3.90 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via an arbitrary trusted key, aka a "skeleton key."