Note that CVE-1999-0524 is about two things: timestamp requests and netmask requests.
Timestamp requests are a bit of a non-issue, since you can assume NTP is being used, so you "know" what time it is on the machines (to the millisecond) without even asking for it.
Netmask requests are problematic since they allow an adversary to map your internal networks, but if you're segmented enough, and the routers/firewalls are dropping the ICMP types 13, 14, 17, and 18, you'll only be able to asks for the netmask from a machine on the same subnet (which already knows the netmask), therefore the response gives no answer that isn't already known.
------------------------------
José Pina Coelho
IT Specialist at Kyndryl
------------------------------
Original Message:
Sent: Fri April 25, 2025 06:08 AM
From: Janos Laszlo Horvath
Subject: ICMP timestamp requests CVE-1999-0524
Dear All,
we have got an ITSec question regarding above mentioned CVE. Our AAC (version 10.0.8.0 + IF2) server has responding :-D such ICMP requests.
Did you have any idea / solution for this? Can we simple ignore this "alert"?
------------------------------
Janos Laszlo Horvath
------------------------------