Description
Multiple stack-based buffer overflows in the NTP time-server interface on Meinberg IMS-LANTIME M3000, IMS-LANTIME M1000, IMS-LANTIME M500, LANTIME M900, LANTIME M600, LANTIME M400, LANTIME M300, LANTIME M200, LANTIME M100, SyncFire 1100, and LCES devices with firmware before 6.20.004 allow remote attackers to obtain sensitive information, modify data, or cause a denial of service via a crafted parameter in a POST request.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2016-4997 | Multiple stack-based buffer overflows in the NTP time-server interface on Meinberg IMS-LANTIME M3000, IMS-LANTIME M1000, IMS-LANTIME M500, LANTIME M900, LANTIME M600, LANTIME M400, LANTIME M300, LANTIME M200, LANTIME M100, SyncFire 1100, and LCES devices with firmware before 6.20.004 allow remote attackers to obtain sensitive information, modify data, or cause a denial of service via a crafted parameter in a POST request. |
References
| Link | Providers |
|---|---|
| https://ics-cert.us-cert.gov/advisories/ICSA-16-175-03 |
|
History
No history.
Subscriptions
Meinberg
Subscribe
Ims-lantime M1000
Subscribe
Ims-lantime M3000
Subscribe
Ims-lantime M500
Subscribe
Lantime M100
Subscribe
Lantime M200
Subscribe
Lantime M300
Subscribe
Lantime M400
Subscribe
Lantime M600
Subscribe
Lantime M900
Subscribe
Lces
Subscribe
Ntp Server Firmware
Subscribe
Syncfire 1100
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T00:10:32.023Z
Reserved: 2016-04-08T00:00:00.000Z
Link: CVE-2016-3988
No data.
Status : Modified
Published: 2016-07-03T14:59:04.523
Modified: 2026-05-06T22:30:45.220
Link: CVE-2016-3988
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD