CVE-2016-1567

Source
https://nvd.nist.gov/vuln/detail/CVE-2016-1567
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-1567.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2016-1567
Downstream
Related
Published
2016-01-26T19:59:08Z
Modified
2025-08-09T20:01:26Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

chrony before 1.31.2 and 2.x before 2.2.1 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via an arbitrary trusted key, aka a "skeleton key."

References

Affected packages