NetApp ONTAP 9.12.1P8 / 9.13.1P4 / 9.13.1P5 Information Disclosure (NTAP-20231215-0001)

medium Nessus Plugin ID 187381

Synopsis

The remote host is affected by an information disclosure vulnerability.

Description

The version of NetApp ONTAP running on the remote host is 9.12.1P8, 9.13.1P4 or 9.13.1P5. It ts, therefore, affected by an information disclosure vulnerability as detailed in the NTAP-20231215-0001 advisory. All SAS-attached FIPS 140-2 drives become unlocked after a system reboot or power cycle and a single SAS-attached FIPS 140-2 drive becomes unlocked after reinsertion. This results in disclosure of sensitive information to an attacker with physical access to the unlocked drives.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to NetApp ONTAP version 9.12.1P9, 9.13.1P6, or later.

See Also

https://security.netapp.com/advisory/NTAP-20231215-0001/

Plugin Details

Severity: Medium

ID: 187381

File Name: netapp_ontap_NTAP-20231215-0001.nasl

Version: 1.1

Type: local

Family: Misc.

Published: 12/28/2023

Updated: 12/29/2023

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v2

Risk Factor: Medium

Base Score: 4.9

Temporal Score: 3.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:N/A:N

CVSS Score Source: CVE-2023-27317

CVSS v3

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 4

Vector: CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:netapp:data_ontap

Required KB Items: Host/NetApp/ONTAP/display_version

Exploit Ease: No known exploits are available

Patch Publication Date: 12/15/2023

Vulnerability Publication Date: 12/15/2023

Reference Information

CVE: CVE-2023-27317

IAVB: 2023-B-0102