CVE-2016-3989 describes a critical privilege escalation vulnerability in the NTP time-server interface of various Meinberg LANTIME and SyncFire devices running firmware prior to 6.20.004. This flaw allows remote authenticated users, by leveraging access to the 'nobody' account, to gain root privileges through writing to unspecified scripts. With a CVSS v3.0 score of 8.1 (High), this vulnerability has a low attack complexity and requires only low privileges, enabling attackers to achieve high confidentiality and integrity impacts. While not listed in CISA KEV, an ExploitDB entry (EDB-40120) exists, and it has garnered some community discussion and media coverage, indicating awareness of its potential for remote command execution and privilege escalation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.0CPE matchmatch criteria | cpe:2.3:o:meinberg:ntp_server_firmware:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:meinberg:ims-lantime_m1000:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:meinberg:ims-lantime_m3000:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:meinberg:ims-lantime_m500:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:meinberg:lantime_m100:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.