CVE-2014-3309

Cisco IOS and IOS XE - Unauthenticated NTP Access Control Bypass via Standard Query

Title source: llm
STIX 2.1

Description

The NTP implementation in Cisco IOS and IOS XE does not properly support use of the access-group command for a "deny all" configuration, which allows remote attackers to bypass intended restrictions on time synchronization via a standard query, aka Bug ID CSCuj66318.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1030549
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/68463
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/94420

Scores

EPSS 0.0211
EPSS Percentile 79.9%

Details

CWE
CWE-264
Status published
Products (2)
cisco/ios
cisco/ios_xe
Published Jul 09, 2014
Tracked Since Feb 18, 2026