Back

HIGH

ALBEDO Telecom Net.Time - PTP/NTP Clock Insufficient Session Expiration

Published Apr 24, 2025

Description

ALBEDO Telecom Net.Time - PTP/NTP clock (Serial No. NBC0081P) software release 1.4.4 is vulnerable to an insufficient session expiration vulnerability, which could permit an attacker to transmit passwords over unencrypted connections, resulting in the product becoming vulnerable to interception.

Affected products

Remediation

Vendor solution

ALBEDO Telecom has identified the following mitigations users can apply to reduce risk:

* Net.Time - PTP/NTP clock (Serial No. NBC0081P) Software release 1.4.4: Update to v1.6.1

For more information, please contact ALBEDO Telecom. https://www.albedotelecom.com/contactus.php

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner icscert
Published Apr 24, 2025
Updated Apr 25, 2025
Reserved Mar 10, 2025
CISA Vulnrichment
Updated Apr 25, 2025
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner icscert
Published Apr 24, 2025
Updated Apr 25, 2025
Exploited since n/a
EUVD-2025-11977