Home / Security / Advisories / NTAP-20160412-0001

NTAP-20160412-0001 — SMB Vulnerabilities in Multiple NetApp Products

Published 2016-04-12 · Updated 2019-12-20 · Status: Final · Exploitation: Public · Severity: HIGH 8.1 · ONTAP affected: Yes

Official advisory: NTAP-20160412-0001 on security.netapp.com ↗. Affected versions, fixed releases, and workarounds live there — this page is a summary.

Product family: ONTAP · Cloud Backup / AltaVault / SteelStore · StorageGRID  |  ONTAP-relevant  |  highest CVSS: 8.1

CVEs in this advisory

What the CVE records say

CVE-2016-3400 — NetApp Data ONTAP 8.1 and 8.2, when operating in 7-Mode, allows man-in-the-middle attackers to obtain sensitive information, gain privileges, or cause a denial of service via vectors related to the SMB protocol.

CVE-2016-3997 — NetApp Clustered Data ONTAP allows man-in-the-middle attackers to obtain sensitive information, gain privileges, or cause a denial of service by leveraging failure to enable SMB signing enforcement in its default state.

CVE-2016-3998 — NetApp AltaVault 4.1 and earlier allows man-in-the-middle attackers to obtain sensitive information, gain privileges, or cause a denial of service via vectors related to the SMB protocol.

Impact

Exploitation of these vulnerabilities could potentially lead to information disclosure, privilege escalation, or a Denial of Service.<br data-aura-rendered-by="305:248;a" /> &nbsp; <table align="left" border="1" cellpadding="0" cellspacing="0" data-aura-rendered-by="305:248;a"> <thead> <tr> <th colspan="1" rowspan="1" style="text-align: left; width: 10%;">CVE</th> <th colspan="1" rowspan="1" style="text-align: left;">Description</th> </tr> </thead> <tbody> <tr> <td colspan="1" rowspan="1" style="width: 10%;">CVE-2016-3400</td> <td colspan="1" rowspan="1">Data ONTAP operating in 7-Mode is susceptible to a SMB man-in-the-middle attack.</td> </tr> <tr> <td colspan="1" rowspan="1" style="width: 10%;">CVE-2016-3997</td> <td colspan="1" rowspan="1">Clustered Data ONTAP is susceptible to a SMB man-in-the-middle attack in its default state due to SMB signing enforcement not being enabled.</td> </tr> <tr> <td colspan="1" rowspan="1" style="width: 10%;">CVE-2016-2118</td> <td colspan="1" rowspan="1">StorageGRID and StorageGRID Webscale relies on Samba, which is susceptible to a man-in-the-middle attack when the SAMR and LSAD protocols are used directly over TCP rather than over SMB named pipes. This vulnerability is referred to as Badlock.&nbsp; <ul> <li><strong>NOTE:</strong> Clustered Data ONTAP is not affected by the vulnerabilities referred to as Badlock as it does not support the DCERPC protocol over TCP. Other SMB-based man-in-the-middle attacks can be mitigated by enabling SMB signing.</li> <li><strong>NOTE:</strong>&nbsp;Data ONTAP operating in 7-Mode is not affected by the vulnerabilities referred to as Badlock as it does not support the DCERPC protocol over TCP. Consult the workarounds section for mitigation of other SMB-based man-in-the-middle attacks.</li> <li><strong>NOTE:</strong>&nbsp;NetApp AltaVault is not affected by the vulnerabilities referred to as Badlock as it does not support the SAMR or LSAD protocols.</li> </ul> </td> </tr> <tr> <td colspan="1" rowspan="1" style="width: 10%;">CVE-2016-3998</td> <td colspan="1" rowspan="1">NetApp AltaVault versions 4.1 and below are susceptible to a SMB man-in-the-middle attack.&nbsp;</td> </tr> </tbody> </table>

Affected products

Official fixes

References

What to do

  1. Check the affected products listed above against the official advisory's affected-versions table — that is where the exact ONTAP 9 release, ONTAP tool, or management product versions are named.
  2. If affected and a fixed release exists, plan the upgrade — see the ONTAP upgrade runbook.
  3. If exploitation is listed as "active", treat remediation as urgent and review exposure (management LIFs, ONTAP S3, SnapMirror endpoints).
  4. Harden in parallel: security hardening baseline and ransomware protection on ONTAP.

Related reading

Browse all ONTAP CVEs → · Security hub