Back

HIGH

ntp: Using port 123 for modes where a fixed port number is not required facilitates off-path attacks.

Published Apr 18, 2019

Description

Network Time Protocol (NTP), as specified in RFC 5905, uses port 123 even for modes where a fixed port number is not required, which makes it easier for remote attackers to conduct off-path attacks.

Affected products

Remediation

Red Hat mitigation

On Red Hat Enterprise Linux 6 and later, switching from ntp to chrony is recommended. Among other design improvements, chrony uses a randomised source port by default. If using ntp, the source port can be randomised by iptables masquerading rules, effectively mitigating this vulnerability: iptables -t nat -I POSTROUTING -p udp -m udp --sport 123 -j MASQUERADE --to-ports 60000-61000

Metrics

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 18, 2019
Updated Aug 4, 2024
Reserved Apr 18, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Apr 18, 2019