Watchguard Technologies, Inc. Information for VU#852879
NTP Project Network Time Protocol daemon (ntpd) contains multiple vulnerabilities (Updated)
- Vendor Information Help Date Notified: 18 Dec 2014
- Statement Date: 19 Dec 2014
- Date Updated: 19 Dec 2014
"Our XTM and Firebox appliances (our main products) are not vulnerable to these flaws, since we use openntpd rather than ntpd.
Our wireless access points are not vulnerable since they only use the basic ntpclient.
However, our XCS appliances (mail security) are vulnerable to the ntpd flaws. We will be releasing a firmware update to fix these flaws as soon as practical. However, in the meantime, we are sharing simple steps to mitigate this issue (use out firewall to block NTP, and point to an internal, updated NTP server instead)."
We are not aware of further vendor information regarding this vulnerability.
There are no additional comments at this time.
If you have feedback, comments, or additional information about this vulnerability, please send us email.