Security Finder

You can use the Security Finder to search for security issues and their impact on Riverbed products. This page is continuously updated, displaying the most current public security issues first. The search box can be used to look up records by specific CVE numbers or relevant search word, e.g. Apache, 8.5.0, Workaround. For additional search tips, refer to article S16165. Security issues listed here are categorized into three groups: fixed, workaround recommended and not applicable.

For general security topics, security best practices and other security related topics, try performing a general search.

BETA FEATURE: This feature is currently under development and is considered Beta Software. We are still enhancing the features and results so please exercise caution when interpreting and implementing the results. If you have any questions, please open a case with Riverbed Support. If you have feedback for this tool, please send it to supportfeedback@riverbed.com.

Riverbed Technology is committed to protecting customers against vulnerabilities in our supported products. Vulnerabilities are addressed in accordance to the software support policy. https://support.riverbed.com/content/support/about_support/end_of_life_policy.html

For search tips, read article S16165.

NTP multiple security vulnerabilities (CVE-2014-9293, CVE-2014-9294, CVE-2014-9295, CVE-2014-9296) (Bug #223251)

Summary
Details:

Multiple security issues were reported in the Linux Network Time Protocol (NTP) library.

CVE-2014-9293: It was found that ntpd automatically generated weak keys for its internal use if no ntpdc request authentication key was specified in the ntp.conf configuration file. A remote attacker able to match the configured IP restrictions could guess the generated key, and possibly use it to send ntpdc query or configuration requests.

CVE-2014-9294: It was found that ntp-keygen used a weak method for generating MD5 keys. This could possibly allow an attacker to guess generated MD5 keys that could then be used to spoof an NTP client or server.

CVE-2014-9295: Multiple buffer overflow flaws were discovered in ntpd's crypto_recv(), ctl_putdata(), and configure() functions. A remote attacker could use either of these flaws to send a specially crafted request packet that could crash ntpd or, potentially, execute arbitrary code with the privileges of the ntp user. 

CVE-2014-9296: A missing return statement in the receive() function could potentially allow a remote attacker to bypass NTP's authentication mechanism.

Not Applicable:

RiOS, in its default setting, is not impacted by any of the above issues.

CVE-2014-9293:  RiOS uses symmetric key cryptography with manually configured keys for NTP authentication. Additionally, its NTP configuration does not allow querying per ntp.org's recommendations for this vulnerability. See
http://support.ntp.org/bin/view/Main/SecurityNotice#Weak_default_key_in_config_auth

CVE-2014-9294: RiOS does not use ntp-keygen to generate auth keys. All keys used in NTP for authentication are entered manually by the user. If the user has entered keys that were generated from ntp-keygen, it is recommended to regenerate such keys.

CVE-2014-9295: RiOS does not use NTP autokey.  Additionally, its NTP configuration does not allow querying per ntp.org's recommendations for this vulnerability. See
http://support.ntp.org/bin/view/Main/SecurityNotice#Buffer_overflow_in_crypto_recv

CVE-2014-9296: RiOS does not use the "crypto" keyword (public key cryptography) in its NTP configuration.

Note: Future versions of RiOS will have the NTP module upgraded to a version that will have these issues fixed inherently.

Recommendation:

No action is needed if NTP on RiOS is being used with its default settings. Appropriate action, such as regenerating keys should be taken if the default settings were changed. For added security, upgrade to a version of RiOS that has the updated NTP module.

Applies To:

All shipping software versions of SteelHead, SteelHead Interceptor, SteelCentral Controller for SteelHead, SteelCentral Controller for SteelHead Mobile