← Back

CVE-2016-3989

nvd nist
Published: Jul 3, 2016Modified: May 6, 2026

JSON object

Loading...
8.1
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Exploitability: 2.8 / Impact: 5.2
Source: NVD

Description

The NTP time-server interface on Meinberg IMS-LANTIME M3000, IMS-LANTIME M1000, IMS-LANTIME M500, LANTIME M900, LANTIME M600, LANTIME M400, LANTIME M300, LANTIME M200, LANTIME M100, SyncFire 1100, and LCES devices with firmware before 6.20.004 allows remote authenticated users to obtain root privileges for writing to unspecified scripts, and consequently obtain sensitive information or modify data, by leveraging access to the nobody account.

Affected (12)

12 products
Ntp Server Firmware
Ims Lantime M1000
Ims Lantime M3000
Ims Lantime M500
Lantime M100
Lantime M200
Lantime M300
Lantime M400
Lantime M600
Lantime M900
Lces
Syncfire 1100
Configuration A
12 vulnerable
Vulnerable SoftwareAffected Versions
Up to 6.0
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions

Related CWEs

References (4)

Source: cve@mitre.org
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.