Home CVE Database CVE-2016-1547

CVE-2016-1547

Description

An off-path attacker can cause a preemptable client association to be demobilized by sending a crypto NAK packet to a victim client with a spoofed source address of an existing associated peer. This is true even if authentication is enabled. Furthermore, if the attacker keeps sending crypto NAK packets, for example every one second, the victim never has a chance to reestablish the association and synchronize time with the legitimate server.

Priority: MEDIUM
CVSS v3: 5.3
Publish Date: Jun 12, 2016
Related ID: --
CVSS v2: Medium
Modified Date: Jun 12, 2016

Find out more about CVE-2016-1547 from the MITRE-CVE dictionary and NIST NVD


Products Affected

Login may be required to access defects or downloads.

Product Name Status Defect Fixed Downloads
Linux
Wind River Linux LTS 17 Not Vulnerable -- -- --
Wind River Linux 8 Fixed LIN8-3927
8.0.0.7 --
Wind River Linux 9 Not Vulnerable -- -- --
Wind River Linux 7 Fixed -- 7.0.0.17 --
Wind River Linux LTS 21 Not Vulnerable -- -- --
Wind River Linux LTS 18 Not Vulnerable -- -- --
Wind River Linux LTS 19 Not Vulnerable -- -- --
Wind River Linux CD release Not Vulnerable -- -- --
VxWorks
VxWorks 7 Fixed -- ntp-1.2.0.2 --
VxWorks 6.9 Fixed -- 6.9.4.9 --

Related Products

Product Name Status Defect Fixed Downloads

Comments

ntp

Live chat
Online