Home / Security / Advisories / NTAP-20160412-0001
NTAP-20160412-0001 — SMB Vulnerabilities in Multiple NetApp Products
Published 2016-04-12 · Updated 2019-12-20 · Status: Final · Exploitation: Public · Severity: HIGH 8.1 · ONTAP affected: Yes
Product family: ONTAP · Cloud Backup / AltaVault / SteelStore · StorageGRID | ONTAP-relevant | highest CVSS: 8.1
CVEs in this advisory
- CVE-2016-3400 — HIGH · CVSS 7.5 · site index
- CVE-2016-3997 — HIGH · CVSS 7.5 · site index
- CVE-2016-3998 — HIGH · CVSS 8.1 · site index
- CVE-2016-2118 · site index
What the CVE records say
CVE-2016-3400 — NetApp Data ONTAP 8.1 and 8.2, when operating in 7-Mode, allows man-in-the-middle attackers to obtain sensitive information, gain privileges, or cause a denial of service via vectors related to the SMB protocol.
CVE-2016-3997 — NetApp Clustered Data ONTAP allows man-in-the-middle attackers to obtain sensitive information, gain privileges, or cause a denial of service by leveraging failure to enable SMB signing enforcement in its default state.
CVE-2016-3998 — NetApp AltaVault 4.1 and earlier allows man-in-the-middle attackers to obtain sensitive information, gain privileges, or cause a denial of service via vectors related to the SMB protocol.
Impact
Exploitation of these vulnerabilities could potentially lead to information disclosure, privilege escalation, or a Denial of Service.<br data-aura-rendered-by="305:248;a" /> <table align="left" border="1" cellpadding="0" cellspacing="0" data-aura-rendered-by="305:248;a"> <thead> <tr> <th colspan="1" rowspan="1" style="text-align: left; width: 10%;">CVE</th> <th colspan="1" rowspan="1" style="text-align: left;">Description</th> </tr> </thead> <tbody> <tr> <td colspan="1" rowspan="1" style="width: 10%;">CVE-2016-3400</td> <td colspan="1" rowspan="1">Data ONTAP operating in 7-Mode is susceptible to a SMB man-in-the-middle attack.</td> </tr> <tr> <td colspan="1" rowspan="1" style="width: 10%;">CVE-2016-3997</td> <td colspan="1" rowspan="1">Clustered Data ONTAP is susceptible to a SMB man-in-the-middle attack in its default state due to SMB signing enforcement not being enabled.</td> </tr> <tr> <td colspan="1" rowspan="1" style="width: 10%;">CVE-2016-2118</td> <td colspan="1" rowspan="1">StorageGRID and StorageGRID Webscale relies on Samba, which is susceptible to a man-in-the-middle attack when the SAMR and LSAD protocols are used directly over TCP rather than over SMB named pipes. This vulnerability is referred to as Badlock. <ul> <li><strong>NOTE:</strong> Clustered Data ONTAP is not affected by the vulnerabilities referred to as Badlock as it does not support the DCERPC protocol over TCP. Other SMB-based man-in-the-middle attacks can be mitigated by enabling SMB signing.</li> <li><strong>NOTE:</strong> Data ONTAP operating in 7-Mode is not affected by the vulnerabilities referred to as Badlock as it does not support the DCERPC protocol over TCP. Consult the workarounds section for mitigation of other SMB-based man-in-the-middle attacks.</li> <li><strong>NOTE:</strong> NetApp AltaVault is not affected by the vulnerabilities referred to as Badlock as it does not support the SAMR or LSAD protocols.</li> </ul> </td> </tr> <tr> <td colspan="1" rowspan="1" style="width: 10%;">CVE-2016-3998</td> <td colspan="1" rowspan="1">NetApp AltaVault versions 4.1 and below are susceptible to a SMB man-in-the-middle attack. </td> </tr> </tbody> </table>
Affected products
- Clustered Data ONTAP
- Data ONTAP operating in 7-Mode
- NetApp Cloud Backup (formerly AltaVault)
- StorageGRID (formerly StorageGRID Webscale)
- StorageGRID9 (9.x and prior)
Official fixes
- StorageGRID9 (9.x and prior) — vendor fix ↗
- NetApp Cloud Backup (formerly AltaVault) — vendor fix ↗
- NetApp Cloud Backup (formerly AltaVault) — vendor fix ↗
- NetApp Cloud Backup (formerly AltaVault) — vendor fix ↗
- Data ONTAP operating in 7-Mode — vendor fix ↗
- StorageGRID (formerly StorageGRID Webscale) — vendor fix ↗
- Clustered Data ONTAP — vendor fix ↗
- Clustered Data ONTAP — vendor fix ↗
References
- http://badlock.org ↗
- https://technet.microsoft.com/library/security/MS16-047 ↗
- https://www.samba.org/samba/security/CVE-2016-2118.html ↗
What to do
- Check the affected products listed above against the official advisory's affected-versions table — that is where the exact ONTAP 9 release, ONTAP tool, or management product versions are named.
- If affected and a fixed release exists, plan the upgrade — see the ONTAP upgrade runbook.
- If exploitation is listed as "active", treat remediation as urgent and review exposure (management LIFs, ONTAP S3, SnapMirror endpoints).
- Harden in parallel: security hardening baseline and ransomware protection on ONTAP.
Related reading
- Common ONTAP problems (FAQ) — plain-language symptoms and fixes
- ONTAP security hardening — baseline lockdown guidance
- Ransomware protection on ONTAP — SnapLock, SnapMirror vaulting, Anomaly Detection
- ONTAP error messages index — EMS/WAFL/NFS/SnapMirror messages
- Every NetApp advisory published in 2016