← Back

CVE-2016-1567

nvd nist
Published: Jan 26, 2016Modified: May 6, 2026

JSON object

Loading...
8.1
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: NVD

Description

chrony before 1.31.2 and 2.x before 2.2.1 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via an arbitrary trusted key, aka a "skeleton key."

Affected (5)

Products: Tuxfamily: Chrony
1 product
Chrony
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Tuxfamily
Up to 1.31.1
Version 2.0
Version 2.1.1
Version 2.1
Version 2.2

Related CWEs

Timeline

No history available yet.