Meinberg manufactures network time servers and synchronization appliances, primarily through its LANTIME product line, which serve as critical timing references across enterprise and infrastructure networks. The observed vulnerability surface concentrates in memory-boundary handling and web-interface input validation, reflecting the firmware and embedded management characteristics of timing appliances. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Meinberg over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-3989HIGH The NTP time-server interface on Meinberg IMS-LANTIME M3000, IMS-LANTIME M1000, IMS-LANTIME M500, LANTIME M900, LANTIME M600, LANTIME M400, LANTIME M300, LANTIME M200, LANTIME M100 | Jul 3, 2016 | 8.1 | 37 | NO | YES |
CVE-2016-3962HIGH Stack-based buffer overflow in the NTP time-server interface on Meinberg IMS-LANTIME M3000, IMS-LANTIME M1000, IMS-LANTIME M500, LANTIME M900, LANTIME M600, LANTIME M400, LANTIME M | Jul 3, 2016 | 7.3 | 33 | NO | YES |
CVE-2016-3988HIGH Multiple stack-based buffer overflows in the NTP time-server interface on Meinberg IMS-LANTIME M3000, IMS-LANTIME M1000, IMS-LANTIME M500, LANTIME M900, LANTIME M600, LANTIME M400, | Jul 3, 2016 | 7.3 | 21 | NO | NO |
CVE-2014-5417MEDIUM Cross-site scripting (XSS) vulnerability in Meinberg NTP Server firmware on LANTIME M-Series devices 6.15.019 and earlier allows remote attackers to inject arbitrary web script or | Nov 5, 2014 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Meinberg.
Media articles that mention a CVE ID that affects a product developed by Meinberg — matched by CVE ID, not by vendor name.