CERT-In Vulnerability Note
CIVN-2023-0391
Multiple Vulnerabilities in NetApp Products
Original Issue Date:December 28, 2023
Severity Rating: CRITICAL
Software Affected
- NetApp SolidFire & HCI Management Node
- NetApp SolidFire & HCI Storage Node (Element Software)
- ONTAP Mediator
- NetApp Converged Systems Advisor Agent
Overview
Multiple vulnerabilities have been reported in NetApp Products, which could allow an attacker to obtain and disclose sensitive information, add or modify data, escalation of privilege or cause a Denial of Service (DoS) attack on the targeted system.
Description
These vulnerabilities exist due to flaw in NetApp products which incorporate Django, Kubernetes, Linux kernel, Intel technology, FreeBSD, Spring Boot, ONTAP Mediator versions prior to 1.7 and AsyncSSH versions prior to 2.14.1 components.
Successful exploitation of these vulnerabilities may allow an attacker to disclose sensitive information, add or modify data, escalation of privilege or cause a Denial of Service (DoS) attack on the targeted system.
Solution
Apply appropriate software updates as mentioned in NetApp security advisories:
https://security.netapp.com/advisory/ntap-20231221-0001/
https://security.netapp.com/advisory/ntap-20231221-0002/
https://security.netapp.com/advisory/ntap-20231221-0003/
https://security.netapp.com/advisory/ntap-20231221-0004/
https://security.netapp.com/advisory/ntap-20231221-0005/
https://security.netapp.com/advisory/ntap-20231221-0006/
https://security.netapp.com/advisory/ntap-20231221-0007/
https://security.netapp.com/advisory/ntap-20231221-0008/
https://security.netapp.com/advisory/ntap-20231221-0009/
https://security.netapp.com/advisory/ntap-20231221-0010/
https://security.netapp.com/advisory/ntap-20231221-0011/
https://security.netapp.com/advisory/ntap-20231222-0001/
Vendor Information
NetApp
https://security.netapp.com/advisory/ntap-20231221-0001/
https://security.netapp.com/advisory/ntap-20231221-0002/
https://security.netapp.com/advisory/ntap-20231221-0003/
https://security.netapp.com/advisory/ntap-20231221-0004/
https://security.netapp.com/advisory/ntap-20231221-0005/
https://security.netapp.com/advisory/ntap-20231221-0006/
https://security.netapp.com/advisory/ntap-20231221-0007/
https://security.netapp.com/advisory/ntap-20231221-0008/
https://security.netapp.com/advisory/ntap-20231221-0009/
https://security.netapp.com/advisory/ntap-20231221-0010/
https://security.netapp.com/advisory/ntap-20231221-0011/
https://security.netapp.com/advisory/ntap-20231222-0001/
References
NetApp
https://security.netapp.com/advisory/ntap-20231221-0001/
https://security.netapp.com/advisory/ntap-20231221-0002/
https://security.netapp.com/advisory/ntap-20231221-0003/
https://security.netapp.com/advisory/ntap-20231221-0004/
https://security.netapp.com/advisory/ntap-20231221-0005/
https://security.netapp.com/advisory/ntap-20231221-0006/
https://security.netapp.com/advisory/ntap-20231221-0007/
https://security.netapp.com/advisory/ntap-20231221-0008/
https://security.netapp.com/advisory/ntap-20231221-0009/
https://security.netapp.com/advisory/ntap-20231221-0010/
https://security.netapp.com/advisory/ntap-20231221-0011/
https://security.netapp.com/advisory/ntap-20231222-0001/
CVE Name
CVE-2021-25736
CVE-2022-3172
CVE-2023-1194
CVE-2023-3893
CVE-2023-3955
CVE-2023-4809
CVE-2023-22329
CVE-2023-25756
CVE-2023-27319
CVE-2023-28376
CVE-2023-34055
CVE-2023-43665
CVE-2023-46445
CVE-2023-46446
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|