NTP.org published a security advisory for thirteen vulnerabilities in NTP software and Boston University published CVE-2015-5300 on Oct 21st, 2015. These vulnerabilities may allow remote unauthenticated attackers to cause Denial(s) of Service(s), disruption of service(s) by modification of time stamps being issued by the NTP server from malicious NTP crafted packets, including maliciously crafted NTP authentication packets and disclosure of information. This can impact DNS services, as well as certificate chains, such as those used in SSL/https communications and allow attackers to maliciously inject invalid certificates as valid which clients would accept as valid.Junos OS Vulnerable CVE-2015-7704 and CVE-2015-7705 http://support.ntp.org/bin/view/Main/NtpBug2901Vulnerable CVE-2015-7853 http://support.ntp.org/bin/view/Main/NtpBug2920Additionally, CVE-2015-7850, CVE-2015-7691, CVE-2015-7692, CVE-2015-7702, and CVE-2015-7855 affect Junos OS and are resolved in the below listed resolved releases.
'host-inbound-traffic'
'protocol ntp'
These issues are being tracked as:PR 1132181 Junos OSPR 1153949 Junos OS only for CVE-2015-5300PR 1133713 ScreenOSPR 1134729 Junos SpacePR 1144300 / 1134726 CTP OS/CTPViewPR 1134747 JSA-Series (Formerly STRM)PR 1134760 WLANPR 1134789 WX OSJunos OS CVE-2015-7703 Not Vulnerable http://support.ntp.org/bin/view/Main/NtpBug2902CVE-2015-7849 Not Vulnerable http://support.ntp.org/bin/view/Main/NtpBug2916CVE-2015-7851 Not Vulnerable http://support.ntp.org/bin/view/Main/NtpBug2918CVE-2015-7854 Not Vulnerable http://support.ntp.org/bin/view/Main/NtpBug2921CVE-2015-7871 Not Vulnerable http://support.ntp.org/bin/view/Main/NtpBug2941Additionally, Not Vulnerable CVE-2015-7701 CVE-2015-7848 CVE-2015-7852 The following software releases have been updated to resolve CVE-2015-5300: Junos OS: 14.2R7 junos:15.1F5-S3 junos:15.1F6-S1 junos:15.1F7 junos:15.1R5 junos:15.1X53-D60 junos:16.1R2 junos:16.2R1, and all subsequent releases.The following software releases have been updated to resolve the remaining issues: Junos OS 12.1X46-D45, 12.1X46-D50, 12.1X47-D35, 12.3R12, 12.3X48-D25, 13.2X51-D40, 13.3R9, 14.1R3-S9, 14.1R4-S9, 14.1R6-S2, 14.1R7, 14.1X51-D75, 14.1X53-D35, 14.2R6, 15.1F4, 15.1F5, 15.1R3, 15.1X49-D30, 15.1X53-D30, 16.1R1, and all subsequent releases.ScreenOS Not VulnerableCTP OS/CTPView Not vulnerable to remainder of NTP.Org announced vulnerabilities.WXOS Not VulnerableJSA-Series (Formerly STRM) CVE-2015-7848 Not Vulnerable CVE-2015-7849 Not Vulnerable CVE-2015-7851 Not Vulnerable CVE-2015-7853 Not Vulnerable CVE-2015-7854 Not Vulnerable CVE-2015-7855 Not Vulnerable CVE-2015-7871 Not Vulnerable KB16765 [juniper.net] - "In which releases are vulnerabilities fixed?" describes which release vulnerabilities are fixed as per our End of Engineering and End of Life support policies.Additional PRs and outstanding CVE's, platforms and products are still being reviewed.This section will be updated as additional fixes for the vulnerabilities are available.
Juniper has published JSA10613 [juniper.net] and JSA10663 [juniper.net] previously to mitigate attacks and exploits against NTP. To mitigate risk of NTP exploits, customers should read and follow the workaround sections of these JSA's.To mitigate these exploits:
2015-10-23: Initial publication2015-10-30: Updated current research for known non-vulnerable and vulnerable CVE's, additional PR details added.2015-11-02: Added Boston University CVE-2015-5300 detail.2015-11-04: Added ScreenOS not vulnerable detail.2015-11-13: Added WXOS not vulnerable detail.2015-11-25: Updated investigation for CTPOS/CTPView. 2 of 13 NTP.Org vulnerabilities are applicable. Boston University CVE-2015-5300 still under investigation.2015-11-28: CTPOS/CTPView is vulnerable to CVE-2015-5300.2016-03-16: Updated JSA-Series (Formerly STRM) problem, solution and workaround sections with most recent details. Boston University CVE-2015-5300 still under investigation.2023-05-12: Added additional CVE details for Junos OS, updated CVSS from 3.0 to 3.1 for heading.