CERT-In Vulnerability Note
CIVN-2024-0071
Linux Kernel Vulnerability in NetApp Products
Original Issue Date:February 28, 2024
Severity Rating: MEDIUM
Software Affected
- AFF Baseboard Management Controller (BMC) - A700s
- Brocade Fabric Operating System Firmware
- FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400
- FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250
- NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S
- NetApp HCI Baseboard Management Controller (BMC) - H410C
- NetApp HCI Baseboard Management Controller (BMC) - H610C
- NetApp HCI Baseboard Management Controller (BMC) - H610S
- NetApp HCI Baseboard Management Controller (BMC) - H615C
- NetApp HCI Compute Node (Bootstrap OS)
- NetApp SolidFire & HCI Management Node
- NetApp SolidFire & HCI Storage Node (Element Software)
- ONTAP tools for VMware vSphere 10
- SnapCenter Plug-in for VMware vSphere/BlueXP backup and Recovery for Virtual Machine
Overview
A vulnerability has been reported in NetApp Products, which could allow an attacker to disclose sensitive information, addition or modification of data, or cause Denial of Service (DoS) condition on the targeted system.
Description
This vulnerability exists in NatApp products due to vulnerable Linux Kernel versions prior to 6.7-rc6.
Successful exploitation of this vulnerability could allow an attacker to disclose sensitive information, addition or modification of data, or cause Denial of Service (DoS) condition on the targeted system.
Solution
Apply appropriate software updates as mentioned in NetApp security advisories:
https://security.netapp.com/advisory/ntap-20240223-0002/
Vendor Information
https://security.netapp.com/advisory/ntap-20240223-0002/
References
https://security.netapp.com/advisory/ntap-20240223-0002/
CVE Name
CVE-2024-0565
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-22902657
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|