Overview
UDP protocols such as NTP can be abused to amplify denial-of-service attack traffic. Servers running the network time protocol (NTP) based on implementations of ntpd prior to version 4.2.7p26 that use the default unrestricted query configuration are susceptible to a reflected denial-of-service (DRDoS) attack. Other proprietary NTP implementations may also be affected.
Description
NTP and other UDP-based protocols can be used to amplify denial-of-service attacks. Servers running the network time protocol (NTP) based on implementations of ntpd prior to version 4.2.7p26 that use the default unrestricted query configuration are susceptible to a reflected denial-of-service (DRDoS) attack. Other proprietary NTP implementations may also be affected. This is similar in scope to DNS Amplification Attacks. In a reflected denial-of-service attack, the attacker spoofs the source address of attack traffic, replacing the source address with the target's address. Certain NTP control messages provide significant bandwidth amplification factors (BAF). |
Impact
An unauthenticated remote attacker may leverage the vulnerable NTP server to conduct a distributed reflective denial-of-service (DRDoS) attack on another user. |
Solution
Apply an Update |
Check if the amplified responses are enabled |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 7.8 | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Temporal | 6.1 | E:POC/RL:OF/RC:C |
Environmental | 4.6 | CDP:ND/TD:M/CR:ND/IR:ND/AR:ND |
References
- http://bugs.ntp.org/show_bug.cgi?id=1532
- http://cwe.mitre.org/data/definitions/406.html
- http://www.nwtime.org/
- http://ntp.org
- http://www.cisco.com/en/US/products/ps9494/Products_Sub_Category_Home.html
- http://www.us-cert.gov/ncas/alerts/TA13-088A
- http://www.prolexic.com/knowledge-center-white-paper-series-snmp-ntp-chargen-reflection-attacks-drdos-ddos.html
- http://www.meinbergglobal.com/english/news/meinberg-security-advisory-mbgsa-1401-ntp-monlist-network-traffic-amplification-attacks.htm
- http://christian-rossow.de/articles/Amplification_DDoS.php
- https://community.rapid7.com/community/metasploit/blog/2014/08/25/r7-2014-12-more-amplification-vulnerabilities-in-ntp-allow-even-more-drdos-attacks
Acknowledgements
Thanks to Christian Rossow for reporting this vulnerability.
This document was written by Michael Orlando.
Other Information
CVE IDs: | CVE-2013-5211 |
Date Public: | 2014-01-02 |
Date First Published: | 2014-01-10 |
Date Last Updated: | 2014-08-26 15:00 UTC |
Document Revision: | 83 |