CVE-2014-3309
Cisco IOS and IOS XE - Unauthenticated NTP Access Control Bypass via Standard Query
Title source: llmDescription
The NTP implementation in Cisco IOS and IOS XE does not properly support use of the access-group command for a "deny all" configuration, which allows remote attackers to bypass intended restrictions on time synchronization via a standard query, aka Bug ID CSCuj66318.
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1030549
Vendor Advisory vendor-advisory
x_refsource_cisco
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3309
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/68463
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/94420
Scores
EPSS
0.0211
EPSS Percentile
79.9%
Details
CWE
CWE-264
Status
published
Products (2)
cisco/ios
cisco/ios_xe
Published
Jul 09, 2014
Tracked Since
Feb 18, 2026