-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2020.4222
Security Bulletin: IBM QRadar Network Security is affected by Network Time
      Protocol (NTP) vulnerabilities (CVE-2020-11868, CVE-2020-13817)
                             30 November 2020

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           IBM QRadar Network Security
Publisher:         IBM
Operating System:  Network Appliance
Impact/Access:     Denial of Service -- Remote/Unauthenticated
                   Reduced Security  -- Remote/Unauthenticated
Resolution:        Patch/Upgrade
CVE Names:         CVE-2020-13817 CVE-2020-11868 

Reference:         ESB-2020.3695
                   ESB-2020.3558
                   ESB-2020.3201
                   ESB-2020.3092.2

Original Bulletin: 
   https://www.ibm.com/support/pages/node/6373164

- --------------------------BEGIN INCLUDED TEXT--------------------

IBM QRadar Network Security is affected by Network Time Protocol (NTP)
vulnerabilities (CVE-2020-11868, CVE-2020-13817)

Document Information

Document number    : 6373164
Modified date      : 26 November 2020
Product            : IBM QRadar Network Security
Software version   : 5.4.0, 5.5.0
Operating system(s): Firmware

Security Bulletin

Summary

IBM QRadar Network Security is affected by Network Time Protocol (NTP)
vulnerabilities of denial of service by flaw in ntpd, relying on
unauthenticated IPv4 time sources in ntpd.

Vulnerability Details

CVEID: CVE-2020-11868
DESCRIPTION: NTP is vulnerable to a denial of service, caused by a flaw in
ntpd. By sending a server mode packet with a spoofed source IP address, a
remote attacker could exploit this vulnerability to block unauthenticated
synchronization resulting in a denial of service condition.
CVSS Base score: 5.9
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/
180011 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)

CVEID: CVE-2020-13817
DESCRIPTION: NTP is vulnerable to a denial of service, caused by an issue when
relying on unauthenticated IPv4 time sources in ntpd. By predicting transmit
timestamps for use in spoofed packets, a remote attacker could exploit this
vulnerability to cause the daemon to crash or system time change.
CVSS Base score: 7.4
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/
183494 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H)

Affected Products and Versions

IBM QRadar Network Security 5.4.0

IBM QRadar Network Security 5.5.0

Remediation/Fixes

+----------------------------------+------+------------------------------------------------------------------------------------------+
|Product                           |VRMF  |Remediation/First Fix                                                                     |
+----------------------------------+------+------------------------------------------------------------------------------------------+
|                                  |      |Install Firmware 5.4.0.12 from the Available Updates page of the                          |
|                                  |      |                                                                                          |
|                                  |      |Local Management Interface, or by performing a One Time Scheduled                         |
|                                  |      |                                                                                          |
|                                  |      |Installation from SiteProtector.                                                          |
|                                  |      |                                                                                          |
|                                  |      |Or                                                                                        |
|                                  |      |Download Firmware 5.4.0.12 from                                                           |
|                                  |      |                                                                                          |
|                                  |      |IBM Security License Key and Download Center and upload and                               |
|                                  |      |                                                                                          |
|IBM QRadar Network Security       |5.4.0 |install via the Available Updates page of the Local Management Interface.                 |
+----------------------------------+------+------------------------------------------------------------------------------------------+
|                                  |      |Install Firmware 5.5.0.7 from the Available Updates page of the                           |
|                                  |      |                                                                                          |
|                                  |      |Local Management Interface, or by performing a One Time Scheduled                         |
|                                  |      |                                                                                          |
|                                  |      |Installation from SiteProtector.                                                          |
|                                  |      |                                                                                          |
|                                  |      |                                                                                          |
|                                  |      |Or                                                                                        |
|                                  |      |Download Firmware 5.5.0.7 from                                                            |
|                                  |      |                                                                                          |
|                                  |      |IBM Security License Key and Download Center and upload and                               |
|                                  |      |                                                                                          |
|IBM QRadar Network Security       |5.5.0 |install via the Available Updates page of the Local Management Interface.                 |
+----------------------------------+------+------------------------------------------------------------------------------------------+

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        https://www.auscert.org.au/bulletins/

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBX8RTjONLKJtyKPYoAQgJkg//daZJVenh+WuL53Zrqt9ahMA7YhRqBYzB
lZwzcy2I8NMfNmkc2r1kNge9A5qLtWpmJS0YFVvS7Zr1q4JVHTdB+i4x5p64/45P
c8v3XlapAZ0caXGKwUwGrdC0k/e4I/QiIvM2H32esGaVCbga5t7VLECvWx2NKhV7
uwWRSsvR/QYvj545NceLtdQMlad5+3TyH9xZbnBCFuwLy4BtwT9mA2mmOi9h9of3
VegPq+tQeJSWmi1Tm8Rey23TIb6ximf9pD48ImBqltT9639GHGY04pH/8KLg9spP
pkr6uhJKigXppdK+VUVzpKaeD5Y68EHWoNskB6279LGnKrDU1MOm6Au6y++H/dGh
fZ3fxdvC76EBI7dOGomMO4zWYP7NSX4yMGmtOTdw02QpxvqXQS6JacoAweS8d8Vq
YlRiqivksZFal1LOKR1xzZCnXlXzPM+z0yWYu7S5mkRdCnrjLm4uTXZBBJkDAb5M
IUe4qlrZq5fdZmjf7ZhLPgSKpkvL9EPegIGGNP5dZDEyJFQTL5WgmjbY8cJOQChs
pl/xqBG7kDiXcGJkSwqY2uFtA6OFGEe6pdMS5afX6arXIudh4pCZwCKkn++1x5j3
PjhlmWWp+6bQjkMQyLstY1QMSpw3/LgvuUMrksLlbyI5uLSAznwfp08ovjLh2oDX
aTdmDxKjR8U=
=KXly
-----END PGP SIGNATURE-----