Database/Control plane, storage & DevOps
ntpd (NTP.org reference implementation): An off-path attacker can block a node's unauthenticated time synchronization
Impact
An off-path attacker can block a node's unauthenticated time synchronization by spoofing the source IP in a server-mode packet. Clock drift is an underrated cluster failure mode: it breaks TLS validity windows, Kerberos, distributed tracing correlation, checkpoint ordering, and any scheduler that reasons about deadlines. An attacker who can freeze your clocks without touching your data plane has a quiet, hard-to-attribute lever.
Who can reach it
Off-path attacker able to spoof source addresses toward the NTP client. Does not require being on the path between client and server.
What to do
Upgrade ntp to 4.2.8p14 or later (or migrate to chrony, which most modern distributions default to) and restart the service. Package upgrade, no reboot. The structural fix is authenticated time — NTS or symmetric-key NTP — plus internal stratum-1 sources rather than public pools; that is a config and topology change and it is what actually removes this class.
References
Related entries
- Ceph RADOS Gateway (RGW): A POST carrying malformed object-tagging XML dereferences a NULL pointer and kills theCVE-2020-12059 · Ceph RADOS Gateway (RGW)High
- Ceph dashboard (ceph-mgr dashboard module): An unauthenticated HTTP request with traversal sequences reads arbitraryCVE-2020-1699 · Ceph dashboard (ceph-mgr dashboard module)High
- IBM Elastic Storage System / Elastic Storage Server (UDP request handling): An unauthenticated attacker who can sendCVE-2020-5015 · IBM Elastic Storage System / Elastic Storage Server (UDP request handling)High
- NetApp Clustered Data ONTAP httpd: A remote attacker with no credentials crashes the ONTAP web server, removingCVE-2021-27005 · NetApp Clustered Data ONTAP httpdHigh
- SPDK iSCSI target (before 20.01.01) and SPDK vhost target (before 19.01): A zero-length PDU sent where data is expectedCVE-2021-28361 · SPDK iSCSI target (before 20.01.01) and SPDK vhost target (before 19.01)High
- Grafana: Unauthenticated directory traversal via /public/plugins/<id>/CVE-2021-43798 · GrafanaHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.