DX Unified Infrastructure Management

 View Only
Expand all | Collapse all

ntp probe security flaw

  • 1.  ntp probe security flaw

    Posted Jan 20, 2023 06:54 AM
    Hi Team

    We are trying to monitor NTP response of all the servers in our environment but when we used ntp protocol on NTP_response probe it got blocked by cisco
    time Devices and when client contacted cisco they came up with below finding
    1. It is incorrect to use ntp packets with mode 6 as (as this is classified as unsecure and possible to use in amplification attack)
    2. Major distributions and NTP server SW does not support mode 6 or defaults to disable it
    • References
          1. RHEL chrony does not support mode 6 https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/configuring_basic_system_settings/assembly_achieving-some-settings-previously-supported-by-ntp-in-chrony_configuring-basic-system-settings
          2. Cisco ratelimits mode 6 packets https://quickview.cloudapps.cisco.com/quickview/bug/CSCum44673
          3. Ntpd https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/6/html/deployment_guide/s1-understanding_the_ntpd_configuration_file

    Can anybody suggest if there is a workaround for this.

    regards
    Nijin


  • 2.  RE: ntp probe security flaw

    Broadcom Employee
    Posted Jan 20, 2023 07:12 AM
    The ntp_response probe has not been updated since Jan. 2017.

    You would have to request an enhancement.

    How to raise an enhancement request for UIM

    Steve

    ------------------------------
    Support Engineer
    Broadcom
    US
    ------------------------------



  • 3.  RE: ntp probe security flaw

    Broadcom Employee
    Posted Jan 20, 2023 07:14 AM
    Since this can be considered a Security flaw, please also open a case and we will enter a defect.

    Steve

    ------------------------------
    Support Engineer
    Broadcom
    US
    ------------------------------



  • 4.  RE: ntp probe security flaw

    Posted Jan 20, 2023 07:33 AM
    Already did stephen 

    Please use below link to access same

    https://community.broadcom.com/idea/ntp-response-probe-using-reserved-mode

    regards
    Nijin


  • 5.  RE: ntp probe security flaw

    Broadcom Employee
    Posted Jan 20, 2023 07:35 AM
    great, ask others to vote it up! and please open a case as well.

    ------------------------------
    Support Engineer
    Broadcom
    US
    ------------------------------



  • 6.  RE: ntp probe security flaw

    Posted Jan 20, 2023 07:55 AM
    Stephen 

    case opened and closed with same statement that this requires enhancement but no update on enhancement made me search for workaround or other ways to monitor ntp jitter between serer and network device.

    So is there any way to speed up this process

    regards
    nijin


  • 7.  RE: ntp probe security flaw

    Broadcom Employee
    Posted Jan 20, 2023 07:56 AM
    The case should not be closed as this does represent a security flaw. What is the case number? I will reach out to our security SME as well.

    ------------------------------
    Support Engineer
    Broadcom
    US
    ------------------------------



  • 8.  RE: ntp probe security flaw

    Broadcom Employee
    Posted Jan 20, 2023 08:40 AM
    Never mind, I found it. Case 33273686 DE550309

    ------------------------------
    Support Engineer
    Broadcom
    US
    ------------------------------



  • 9.  RE: ntp probe security flaw

    Posted Jan 20, 2023 09:21 AM
    Stephen 

    Will raising this as defect speed up a new release for this issue with NTP ?

    Regards
    Nijin


  • 10.  RE: ntp probe security flaw

    Broadcom Employee
    Posted Jan 20, 2023 09:35 AM
    Im working on it, will let you know after my discussion with our Security team.

    ------------------------------
    Support Engineer
    Broadcom
    US
    ------------------------------



  • 11.  RE: ntp probe security flaw

    Posted Jan 24, 2023 05:37 AM
    Hi Stephen

    Have you got any update on this from security Team?

    Regards
    Nijin




  • 12.  RE: ntp probe security flaw

    Broadcom Employee
    Posted Jan 24, 2023 08:37 AM
    Ive sent a reminder to the Security team, and Ill let you know as soon as I hear back.

    Steve

    ------------------------------
    Support Engineer
    Broadcom
    US
    ------------------------------



  • 13.  RE: ntp probe security flaw

    Broadcom Employee
    Posted Jan 26, 2023 07:22 AM
    This request has been added to our backlog and shall be reviewed for prioritization in our next meeting. 


    ------------------------------
    Principal Product Manager
    Broadcom Software
    ------------------------------



  • 14.  RE: ntp probe security flaw

    Posted Jan 30, 2023 07:59 AM
    Hi Ravishu

    Thanks for update

    When can I expect update on this, when will next meeting take place?

    Regards
    Nijin




  • 15.  RE: ntp probe security flaw

    Posted Feb 06, 2023 03:00 AM
    Hi Ravishu

    Did you have your review meeting can you please confirm if there is any update on ntp_response probe defect.

    Regards
    Nijin




  • 16.  RE: ntp probe security flaw

    Broadcom Employee
    Posted Feb 06, 2023 04:02 AM
    Edited by Ravishu Arora Feb 06, 2023 04:02 AM
    Hi Nijin,

    Recognizing the urgent need, we have indeed planned to initiate the work needed for this request. However, it would be helpful if we can get in touch with each other to ensure that the solution matches the needs. Can you please email me at ravishu.arora@broadcom.com so that I can set something up on the calendar with our technical team?

    ------------------------------
    Principal Product Manager
    Broadcom Software
    ------------------------------



  • 17.  RE: ntp probe security flaw

    Broadcom Employee
    Posted Mar 19, 2023 12:36 AM

    An updated NTP_Response probe release which fixes this concern is now GA:

    https://community.broadcom.com/enterprisesoftware/communities/community-home/digestviewer/viewthread?GroupId=1315&MessageKey=dc0400dc-776b-4964-a866-7b9bf8a3e07d&CommunityKey=170eb4e5-a593-4af2-ad1d-f7655e31513b



    ------------------------------
    Principal Product Manager
    Broadcom Software
    ------------------------------