<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NTP Vulnerability issue -- CVE-2014-5209 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ntp-vulnerability-issue-cve-2014-5209/m-p/3402066#M902330</link>
    <description>&lt;P&gt;Cisco is pretty good about owning up to vulnerabilities and releasing patches. That one just didn't show up in my search.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What device and software version is the scanner reporting against?&lt;/P&gt;</description>
    <pubDate>Tue, 19 Jun 2018 17:58:05 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2018-06-19T17:58:05Z</dc:date>
    <item>
      <title>NTP Vulnerability issue -- CVE-2014-5209</title>
      <link>https://community.cisco.com/t5/network-security/ntp-vulnerability-issue-cve-2014-5209/m-p/3398478#M902310</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;Could somebody please advise how do I fix the below vulnerability issue as I couldn't find any solution for it. Is this vulnerability a concern?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Vulnerability Description&lt;/P&gt;
&lt;P&gt;--------------------&lt;/P&gt;
&lt;P&gt;An NTP control (mode 6) message with the UNSETTRAP (31) opcode with an unknown association identifier will cause NTP to respond with two packets -- one error response packet indicating that the association identifier was invalid followed by another non-er&lt;/P&gt;
&lt;P&gt;CVE-IDs --&amp;nbsp;2014-5209&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The only config I have on the router for ntp is&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ntp peer x.x.x.x&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Kris&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:52:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-vulnerability-issue-cve-2014-5209/m-p/3398478#M902310</guid>
      <dc:creator>krisvamcee</dc:creator>
      <dc:date>2020-02-21T15:52:27Z</dc:date>
    </item>
    <item>
      <title>Re: NTP Vulnerability issue -- CVE-2014-5209</title>
      <link>https://community.cisco.com/t5/network-security/ntp-vulnerability-issue-cve-2014-5209/m-p/3400752#M902317</link>
      <description>&lt;P&gt;NTP has been the source of numerous reported vulnerabilities over the years. The particular one you mentioned though doesn't appear to affect the most common Cisco software (such as IOS and ASA).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you have a specific reason to suspect it affects your equipment?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In general, you should run the Cisco-recommended release (as indicated on the downloads page for that product) that both supports your hardware and addresses any significant security vulnerabilities according to the product release notes.&lt;/P&gt;</description>
      <pubDate>Sun, 17 Jun 2018 07:37:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-vulnerability-issue-cve-2014-5209/m-p/3400752#M902317</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-06-17T07:37:40Z</dc:date>
    </item>
    <item>
      <title>Re: NTP Vulnerability issue -- CVE-2014-5209</title>
      <link>https://community.cisco.com/t5/network-security/ntp-vulnerability-issue-cve-2014-5209/m-p/3401493#M902324</link>
      <description>&lt;P&gt;Thanks Marvin.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I got this from the vulnerability scan report, although the severity is low, just want to know if we can fix this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Kris&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jun 2018 23:59:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-vulnerability-issue-cve-2014-5209/m-p/3401493#M902324</guid>
      <dc:creator>krisvamcee</dc:creator>
      <dc:date>2018-06-18T23:59:06Z</dc:date>
    </item>
    <item>
      <title>Re: NTP Vulnerability issue -- CVE-2014-5209</title>
      <link>https://community.cisco.com/t5/network-security/ntp-vulnerability-issue-cve-2014-5209/m-p/3402066#M902330</link>
      <description>&lt;P&gt;Cisco is pretty good about owning up to vulnerabilities and releasing patches. That one just didn't show up in my search.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What device and software version is the scanner reporting against?&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jun 2018 17:58:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-vulnerability-issue-cve-2014-5209/m-p/3402066#M902330</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-06-19T17:58:05Z</dc:date>
    </item>
    <item>
      <title>Re: NTP Vulnerability issue -- CVE-2014-5209</title>
      <link>https://community.cisco.com/t5/network-security/ntp-vulnerability-issue-cve-2014-5209/m-p/3402311#M902337</link>
      <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It's&amp;nbsp;ISR4431/K9 and version is&amp;nbsp;03.16.04b.S.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Kris&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jun 2018 02:54:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-vulnerability-issue-cve-2014-5209/m-p/3402311#M902337</guid>
      <dc:creator>krisvamcee</dc:creator>
      <dc:date>2018-06-20T02:54:54Z</dc:date>
    </item>
    <item>
      <title>Re: NTP Vulnerability issue -- CVE-2014-5209</title>
      <link>https://community.cisco.com/t5/network-security/ntp-vulnerability-issue-cve-2014-5209/m-p/3402746#M902340</link>
      <description>&lt;P&gt;There's nothing in the release notes for that version (or others in the releases after it) that mention that vulnerability. I suspect your scanner is reporting a false positive.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jun 2018 15:13:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-vulnerability-issue-cve-2014-5209/m-p/3402746#M902340</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-06-20T15:13:36Z</dc:date>
    </item>
    <item>
      <title>Re: NTP Vulnerability issue -- CVE-2014-5209</title>
      <link>https://community.cisco.com/t5/network-security/ntp-vulnerability-issue-cve-2014-5209/m-p/3403057#M902342</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yeah maybe. I will wait until next report comes out.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jun 2018 02:34:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-vulnerability-issue-cve-2014-5209/m-p/3403057#M902342</guid>
      <dc:creator>krisvamcee</dc:creator>
      <dc:date>2018-06-21T02:34:41Z</dc:date>
    </item>
    <item>
      <title>Re: NTP Vulnerability issue -- CVE-2014-5209</title>
      <link>https://community.cisco.com/t5/network-security/ntp-vulnerability-issue-cve-2014-5209/m-p/4071108#M1069377</link>
      <description>&lt;P&gt;Hi, Marvin&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;I also hit this issue&amp;nbsp;&lt;SPAN&gt;CVE-2014-5209 in customer field. But I can not find any information from Cisco security center&amp;nbsp;&lt;A href="https://tools.cisco.com/security/center/publicationListing.x" target="_blank"&gt;https://tools.cisco.com/security/center/publicationListing.x&lt;/A&gt;. Do you know where I can find more information of&amp;nbsp;CVE-2014-5209 then I can judge whether customer's devices were impacted.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Fei yang&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Apr 2020 03:48:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-vulnerability-issue-cve-2014-5209/m-p/4071108#M1069377</guid>
      <dc:creator>feiyang2</dc:creator>
      <dc:date>2020-04-22T03:48:38Z</dc:date>
    </item>
    <item>
      <title>Re: NTP Vulnerability issue -- CVE-2014-5209</title>
      <link>https://community.cisco.com/t5/network-security/ntp-vulnerability-issue-cve-2014-5209/m-p/4071126#M1069378</link>
      <description>I could not find the CVE cited in any Cisco publicly published security advisory or bugID. 
However I did find the following two BugIDs that should be of use in determining whether your customer's equipment is affected by the underlying ntp mode 6 and mode 7 vulnerabilities:
&lt;A href="https://quickview.cloudapps.cisco.com/quickview/bug/CSCum44673" target="_blank"&gt;https://quickview.cloudapps.cisco.com/quickview/bug/CSCum44673&lt;/A&gt;
&lt;A href="https://quickview.cloudapps.cisco.com/quickview/bug/CSCtd75033" target="_blank"&gt;https://quickview.cloudapps.cisco.com/quickview/bug/CSCtd75033&lt;/A&gt;</description>
      <pubDate>Wed, 22 Apr 2020 04:44:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-vulnerability-issue-cve-2014-5209/m-p/4071126#M1069378</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-04-22T04:44:38Z</dc:date>
    </item>
    <item>
      <title>Re: NTP Vulnerability issue -- CVE-2014-5209</title>
      <link>https://community.cisco.com/t5/network-security/ntp-vulnerability-issue-cve-2014-5209/m-p/4071127#M1069379</link>
      <description>&lt;P&gt;Thanks, Marvin.&lt;/P&gt;
&lt;P&gt;I will check it.&lt;/P&gt;
&lt;P&gt;Fei Yang&lt;/P&gt;</description>
      <pubDate>Wed, 22 Apr 2020 04:53:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ntp-vulnerability-issue-cve-2014-5209/m-p/4071127#M1069379</guid>
      <dc:creator>feiyang2</dc:creator>
      <dc:date>2020-04-22T04:53:23Z</dc:date>
    </item>
  </channel>
</rss>

