A security scan may report CVE-1999-0524 on Greenplum Database (GPDB) nodes. For details on the vulnerability see : CVE-1999-0524
The remote host answers to an ICMP timestamp request.
This allows an attacker to know the date that is set on the targeted machine, which may assist an unauthenticated, remote attacker in defeating time-based authentication protocols.
Greenplum Database clusters require ICMP to be enabled on the interconnect network for "ping" operations, which check host availability and cluster health. By default, many Linux distributions respond to all ICMP request types.
To mitigate the vulnerability without disrupting Greenplum interconnect heartbeats, block only the specific ICMP timestamp request and reply types using iptables.
iptables-services: